MalScore
100/100
MalFamily
Adware

OfferInstaller_dotnet2.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 49/60 Related 2134
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 378.00 KB (387072 bytes)
Compile time: 2015-07-22 09:15:32
MD5: 5abf5e44b169139e1da5b8b92378ed0b
SHA1: 05c04443c43c27f2728014817b1265594b79dbff
SHA256: 3424b4568ca575548ec226724efe7a5a369df3ee9bcc49a8a43642fbbcdbc8bb
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 4 import resource debug relocation
First submission: 2017-04-11 14:08:16
Last submission: 2017-09-29 12:04:49
Filename detected: - OfferInstaller_dotnet2.exe (4)
URL file hosting
hXXp://shooky-14-06-2015.s3-website-us-east-1.amazonaws.com/22.07.2015/OfferInstaller_dotnet2.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2017-03-11 03:57:42 [49/60] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x5d444 382464 7703914a241c44fd13c2a0054815f9ff bda16ad84a29c72124aac89f4d48d188baf762a2
.rsrc 0x60000 0xe00 3584 ca35bfe984ff1381b86f69bf53c0ede2 3ee8eaab770e8aaef5a5d5306d8bab514b9a9bd6
.reloc 0x62000 0xc 512 f2074b860b740500718bbba8bfb7c3a1 817a5edc9f3e852e6edbcb8c2b15d203fbe2351c
PE Resources
Name Offset Size Language Sublanguage Data
RT_VERSION 0x600a0 768 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_MANIFEST 0x603a0 2612 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright \xa9 2014
Assembly Version: 1.0.0.1
InternalName: OfferInstaller_dotnet2.exe
FileVersion: 1.0.0.1
FileDescription: OfferInstaller
OriginalFilename: OfferInstaller_dotnet2.exe
Translation: 0x0000 0x04b0
ProductVersion: 1.0.0.1
ProductName: OfferInstaller
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Compressed
costura.newtonsoft.json.dll.zip
costura.icsharpcode.sharpziplib.dll.zip
ICSharpCode.SharpZipLib.Zip
FIle type: Library
mscoree.dll
IP Found
1.0.0.1
URL(s)
http://json.
http://events.
http://www.w3.org/2001/XMLSchema-instance
JLE3Z0WM93NR
6P1ZCL5B7KTE
6SCGZRVTMGJU
204823CVRZEF
OfferInstaller_dotnet2.exe
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http
LRIGIWHA9F5J
Problem in DownloadAdditionalFile function, unable to delete file, error:
C4Y0LKIA1ABN
69JW1KD9VUBD
ND7925B28LMO
WF1UM1I0ZHQE
InternalName
ZQ15F3BIFF9Y
IVFHDZSMIF6Y
4SK7ADU72610
HRPII11F1XEK
Select * from Win32_ComputerSystem
AntiVirusProduct
WZRSAX2BNLJ0
000004b0
JV8JLHZTBJFO
GZTEOTIE0OXV
SXV5MDOQMK8X
Q3NHNGO7ACK0
0BZWW5HQNWH5
7SCGQK3QOH4P
ZBILO61KG73D
IFTDK3TCP3IA
VirtualBox
LegalCopyright
9GB21I2NVJY0
25FT0EHGYH4G
7KG0X786LVWQ
L02SL5TED1HR
FQ0SR9PVRDDK
W0LQJ0RV2CE6
84OZZ0K17O00
KWL3JOXHAEWS
CBLT6LXFMVO6
2FP1KBZWJUG7
R3MG4Q2MIX0L
{0}.{1}
NX6K1JH3LWNE
CD4M9LJTYLPG
HQM7OZ5UZ8OJ
PAI3QSHVXAEO
vmware
pub_id
3O6QIXWENU2Z
72DIVM5O3LXS
5DB55V55AQMT
BTKFGH4V6VCM
OSFR5EV4TN3H
01LNMZPABALH
V1B1WDRSVMGD
5VJULR45S5T4
R5FE1ELDRTBJ
AVFOBOI4V4TZ
{{[^}]*}}
TLRXL8YJIUTT
8A1CALLS99HM
425N5C5GHYIL
9ZUMTT05KYFV
Problem in RunInstallProcess function on WaitOne, error:
E6P9EWS3L000
101
LDX67WGEJV3N
J95388FPX3CZ
YYNZNTHND8XU
DIQHEDA8AOO0
F2A6H7LJG876
Problem in InstallAdditionalFile function, error:
36VMUK7M3KRS
NN8RP3MBQJ12
J4QMFVI3FJGO
XT8SAYCH4SDG
.exe
ClassesRoot
adv_id
ZipKey
KLZV1LPFK6HR
0PF0LKOLMIMF
D0OXIN5PQDQ9
RGBBRJKN0ME4
J9RZIGL43Q44
PIHGDS9JOB5P
JYUB06UPA064
txt
zip
costura.newtonsoft.json.dll.zip
B4FIL67O4RBV
SRSRD5HYGGAH
RZOMCBM5WFZV
12FUPTSCX89K
I2C3OQJ2T6JR
W4I04O9AWFFN
BAJYRVIT89YS
9Q794J4DU6GW
8XIBMZ66ZC6Q
FICHJ2WVGF1L
QJT9RNYTMY4V
46AIGFRZW1WJ
XO46LI3YH4D7
\adv_
AI5NZM2W88NB
95I655AWUQM5
ZGS90CO1N3NY
72A0FV6NTX8S
2XS9KUXF0459
MEIV5YTCFMX2
JPTUZ4SAFP3W
95PCW3SEA3R5
Problem in CheckIfRegKeyExists function, error:
Parsed advID is 0
ZZBAGI47LE2V
adv_
.txt
cab
VPKG0DBZ8HMA
SFZ9HFZEA9UD
newtonsoft.json
http://json.
PDG2XHNRP3TL
Q1FGPSSR7RL6
1AF3FUNDHFVA
WVTEWEUHMMQ9
pub_id=
69S9YIBWNJVM
QYMPR69KWUNV
Q2Z07CHN9BS0
\Extracted\adv_
4G11SINX9WHZ
DJNLVNQDAWM7
Problem in DownloadAdditionalFile function, unable to download file, error:
6RMG1KRP8MLS
-exitCode=
OTZIX3PAMKE5
-av=
H5J56DPNXIIL
35HK1Z485F4N
GCSVZT3D30JV
GA7JGVSRIZ15
AWDRMX4FE2X0
1DFXGLJU4EGB
RE84TTI9IPQX
W7LKL33RNRN7
HB8ZVIBS8RE6
Problem in InstallAdvertiserFile function, error:
C82SCLAGSBDT
&lang=
Model
66V6ATTZOMPV
VEV5PQ5SHPCD
OriginalFilename
TDNK10NB2BLI
&dotnet=
KNHXMJSHRE1G
FIIPSOWOVJ7Z
OS5KC2Y78FX5
MX2W8UMQLHMJ
ZHIQU05FYJQN
8JPO23CAG4ES
6YZ2N6Y88BSE
9GP7OGBTQF7O
3GJ521N0SE2O
UKP18X8T4OI5
0S5P4PPS23OW
HAUR0I6RIH6K
W10EO5AVE170
UVH09VWTZOXL
VJO6Z42K8UWH
Q07BK66B6R7C
B0BCJ3BYGORI
Y7JX5NS4ASU4
43YZ9CPT2KJV
S4Q575IGIRUU
XF2KMVG9SPWP
OT9S1ELX1M5Z
OTB2T5GZVOSN
Problem in RenameFileAndUnzip function, error:
-reason=Unsucessful_Download
BM3MHRDN3IXF
TRMDG2CR1P4H
path:
L8P4OEWWMKUI
J8MWRTK9VG93
WRLKF8JR5QMN
ZJ8IWUV1YOBZ
YMS6YL28O7RT
5LYZPD8UYAK9
QMBI6J8AM8KP
5SZ93H2RYND2
2O4PI12J4ZLP
SCQKNA5XJENF
WHRD7N5YYS71
J7O2PENSC252
SCS2M9XJ3UD1
TNR6B3F7QXKP
TH5VS30IOWH1
5PRF0RELWGTO
DWOZ6W0CYPA2
QP2FNV9NQR56
9L9PFHTT14FJ
7B8LZ66M4CRB
IKKQYJE3G1PA
Problem in DownloadAdvertiserInstallFile function, error:
MachineGuid
NFB82QU7PABK
domain
MDLCTJH1IHRQ
ProductVersion
OBV6CJ9HROAN
GUQS22PQZNVM
X9GUM0NVUC5B
9GHKPSUE3GD8
G05AO7YB52O6
01ZJV9U9XBA2
SOFTWARE\Microsoft\Cryptography
1A4QU0TKIAEK
66AUQLHVSOWN
E7N4UYM6ALX6
KJWVJCQ2F0AS
FileVersion
1EAWSBHOO2A6
&osver=
C010SY5DS1TC
TEMP
QGWX0UP7NALQ
FWJMXYXUGKAM
LocalMachine\
LUK2LI1Y0FCN
N5CPSXRIVSMA
5DFUBJTWW6P9
9CUDD71PT6QM
5E132A9A386X
0D3TE02KXJXF
I6SLAX6ZTPN7
8BEMB8AVVKZ4
P99NRLTELHND
MA9E8UFEAV3I
HD0OL8BSG3GE
CJBAHRIAEK5F
XR8051O383PD
L2NE4NQA0JK9
TRE1C9894IJD
O0NUM387DRRH
34DE5ZPXCPKM
TX4GCXHF4EO6
PF09GARRRB7Y
0424P90LLM0B
OIWN3DHLX8YF
costura.icsharpcode.sharpziplib.dll.zip
R1CD146J369Q
3GBAFLK7G042
EA8AV2DN7RM1
Y5A01WN0HJPD
9MZAF0TV156M
ZS68SMUYJQT4
W4CWGKW4C42D
FS2FYLL35F4N
81AB4U3FM8XP
IS1DQ8QN1EP1
84PN9NNT0777
J6SGUQF3W8C6
PKB1BITP6HF9
PRVZNIVO2616
WR9DX180CBWT
T865NAMP0GW4
Q8F9C9JCGTOY
C47Y0NP4EJNO
OD0LLTKR9W4H
VS_VERSION_INFO
KKMY4GXHUJL2
&dwb=
7BRHMCYQAXZI
42MHXPUPQ7MO
1GIE1JLUSFVG
QY7ILR23NY84
Software\Clients\StartMenuInternet
GING46S25SUO
QPO3BMGBB3I4
6XN27BU1EG6I
YW3AAXPJ4BIX
AVB9EPCDITAN
OY4GO5P5P7XJ
T69ZGZATOEYY
root\SecurityCenter2
0CMPYKJJLBRF
FYLV86NOA949
N3NAELPZ833V
BV5G4Z7X6PXI
R092UICP3Q96
IEYZAHF4K1S0
2ZLSOF56HSN6
68MERBNCCCG1
OfferInstaller global start direct
1ZGLNMAA2AR9
7KMW3BWBVLW2
CJ47KQI2BG5T
NAVFEU1QBXDZ
error getting advertiser with proxy, trying now directly
WGSNH80Y65E5
0S0KG7D0JJDY
VTDFQQMG8B1I
6L7UVKBJC0BB
5ROYP03NAYTH
2CNCEUXFP8MK
Lxy
97STNSE5ZCRL
VB4HFFPS4WSX
XTQPI0Y5H8X1
PRVEXBYTK269
03RV6L1MDICF
BWQEBWWTT0R2
0PKJXCZ4WKXH
Problem in checking virtual enviroment, error:
BA76V4S8XDRG
V495NADGM6PP
BLJ8TAPSWR9Z
QN4AP5J694MY
/?p=
IYNO93BXI3TS
S8KLNANDEG2S
MRF5GUD2MO72
H4TZ41HSTWN7
O50Y32ATTFJH
N9JG3WATZ4ZC
NDHY04G8N9I3
exe
displayName
6ZSFICZ0C4F0
AZB5DMLUQ8SC
FY7BCBG7B7IM
161WU0CZZ6R1
OfferInstaller.Properties.Resources
XUBTHFAGAOPC
I4BH8I5TG0NC
SY39KHODW6U1
OfferInstaller
X9ZJZ8J369RN
http://events.
OTFATHNM58C8
KYXO6AWKL6VV
DMNX5ASP0C2C
RJSKZLJI9HDP
E60II4PE2CIL
N5D2EHHRJCX2
OY0T1144W76M
J88S8BANN5PC
\Extracted\additional_
G3UNXZ7EUCMX
1.0.0.1
TD347BGZM8OQ
S2DMG3FBGLTX
offer_version=
Problem in GetAntiVirusInfoString function, error:
Translation
8XHJPV72UEU5
U0FCP23UCELH
RYGW1HE1029R
System.Net.Configuration.SettingsSectionInternal
-event=6
8LS0Q09EB5OQ
6CDWSOOPLKE5
SS5OHJPO05IU
U35KJXDW1SOI
QTVOTHPSN17X
371LX07ZKGV3
6ZKGFTZ1I0W2
FRKN57IKLIPG
32DD9AU70WP2
T9NPP8F9Y4LD
IUFFEJUH0UAP
Problem in RunInstallProcess releasing mutex function, error:
URHYIT78434C
07U8NU936H0B
R1PLTI3AY6CN
S9W9IS43HQST
MUDPLC44I1HK
BJRBY0SBH6HI
FXBEIRC24QUN
WKSBFB4JRFQU
3Q72LBZAU0Q8
BI_Version
RA5B1WS9EDWX
43BDCCN0VDMH
Problem in DownloadAdvertiserInstallFile function, unable to delete file, error:
-pubid=
Problem in RunInstallProcess function (new mutex), error:
KCMPU7JEBR64
50ANMPLF183R
06VJ02QO8FXK
3N8N4NFBTHFK
9XKVHN5C79EB
KOP814I30JJA
RAVHXSW571TK
9LEMWY51IYSC
28FKASOWKARO
R39W1TSP5IKQ
noproxy
GET
MHVT87OYSC38
SYCJ0OF78FZZ
3DE3MF5XYFCW
KZZHA7V7XI5W
LUBQAIO40NN6
7WFFFTNQMWZH
3Z5021AOS2R4
HLDJ1CC48G3X
2EZTAFGY5VPZ
2KGV2S3QHDGJ
J929MA4C3R4Y
&setup_id=
QICK78NG1FC8
GHQ45MJGHGHC
VW17MKC9425J
54VMBT68371F
PF4XQ2TJTQ59
3UP1YRS19VI6
32ZT8AG1UP3G
ESEQV5H4OD8N
YSYHL0IFIYAE
FHDD2QGYEBAR
VWEZEXM5L8X3
3HXWW8UMU9UR
Problem in Download Json file with proxy
OSTKKGMUCPX9
T1LWZAFSJN8R
CWB536NO4ERY
FL340VTHAGCF
T9LUSP1WLCJW
W9KRGA4VRRX2
G2KFDM847HK4
MBTMZG79CGNM
EG7UJ4DCL110
5TARUBSWYYB4
Copyright
3MSPRYUBO9RF
42OZGK4VTGTH
V0YBHNLVNF7V
Problem in getting list, error:
KCY4X7CQQ7HN
U8DFP1VK6ENK
NRNQQBFYU8E4
2OKDL4J7NKO5
2UEJHS2BN6B6
4JZU0PTKXTLT
KUK6MI4JXGKB
YWVNW27W9V8B
F3VEIISY9U06
fastmediaplayer.net
XO7RRXXY4RDR
X479CK27BMIV
URB0RLRMXD2W
MZX6633ALA9J
U3OIQ2875GWZ
K0TT00ZR4U9I
CTWPRR9WJ8C4
5SZ4Q9BIIN8P
7TSRTC1N4XX2
Problem in RunInstallProcess function, error:
1ME77NVES6PP
2014
KO3KM20UMH85
Domain was not passed
V6AKTTHGI30J
5QEJLCD70DCW
\additional_
ERYEM0XV3GL3
WBWN8I57Z66T
-biVersion=
{{MGUID}}
4490PDFYIQ3Q
VFF4WPT6Z6SK
4USY3DBQTS07
2HBN64S9VK8W
OVUB2OPJKQX0
FATR3NMOYVAD
6ZTP8HEZ8ZND
6XLTNC8FLMSU
N938KRYDBU12
Y6HZZRX36U3T
4LIIVHR79QZS
FNY6C5I59Y25
FileDescription
YYOV3I0SL8UQ
QPSAMPURTM1F
F6FDNWRMNEVE
-installParams=
9IYC7MLTBUYQ
8FFDYB636JFM
02N9WY9R6N61
SELECT * FROM
N1D6MC4J7NCX
7N4L6RSOYAUM
2ZLC1Y9OSWBR
BYJWAQKOILBC
ECL16TKIEFPN
BCH4GILT23ZR
3N2OW14YDNOR
6HREJ1UVEK9S
useUnsafeHeaderParsing
6JO654S4S1CK
OBX5XVD502I6
SLCLGQB7RTYL
RN3HGXDY53RF
DB3N2GKHLGIS
HQQTWSEGE631
JGLOZZT3S08L
microsoft corporation
-event=
OYX7S9FI2LXD
GPVR2BPM7HK6
PC001U6YFCNQ
T34D8Y56SICS
5DA1975NFNV0
SUMY8QPRWUI8
0209N1BSX6LD
StringFileInfo
E7O800MHJNBI
HOVBJM1EUNTW
RIFQIHR3JA0T
PZ9XXD97WXZ9
GKKM5TEGF3Q5
W66RMQ8D8LZ0
S5OX7527UDLR
N5NRBDZKFFOS
F90URFH2T9T7
JXPBLTG1ZMT0
UX78PT5HT2FQ
27Z5XTKOV9P7
ZGFNB6VWRLI9
UA1D73O6S6R5
2BCWH9NB4T7X
6HXQZP5CLGGY
KIGM9UM9ACKF
ODBQ7RQCS0L8
Section
9BPFH9ZIESCZ
39OB0YXH7AMC
BH3KFGH6QZJK
111
4CZ0XKUQRVW4
T1RBLAI4GUW1
68D5FLEXKX0G
.zip
J30XL262THTZ
97K3TRTYG549
S18VC6VM4ZLF
-reason=
FMRE7GG0C6TW
323XADHUOCW0
JPISAKNT2K0U
error advertiser is null
PXQZA0KEWPTY
LD25PHZJHN66
GDGMNMOQCTY8
301BFLSS7BWC
IJW2WOZVJSSF
FR96ZSZZVLI5
IZE6JJSJ5K24
HILUWLJ53GKB
N6H3HK3PP993
M0EV3K3LPSH4
DWN6FO7ETTFQ
G2UB65GB5II4
Global\
LEQVCQ1XX158
4I5QHAX81X6U
3R075OP1OEYQ
O1NIZZ558F67
IMG9D2MNJ1FK
7TYLZ3YV2ORG
6XB769LLGCEF
FO9TQWZVF14P
ProductName
LocalMachine
XOR512ZMPYE1
DMZ3BYW27NZ2
RC56W4EV1T85
MCM14LWKDKW9
L3T8VZLKKA4B
-advid=
AEKZ3VSB3EAH
4YHFXZW8YCP8
NIR6IM4ZBYW6
adv_id is empty or was not supplied
additional_
-reason=Unsucessful_Json_Parse
ZWV8UNGTA2EU
XYYHPNCQQNEC
XCRX6N4NDZ65
SQH20DY0JRI7
-event=99
1T50HDSEBC1C
O3AS3K2YSWZ7
UUMBLYRP5VA0
VarFileInfo
LLCI8IJ35MQL
Manufacturer
25WT5DN7L3QI
96SM6VFEK0TL
R1JEB86Q539Z
BAW0256Q9DAL
0JB1BN31OVMD
Y518AFWU2MXC
icsharpcode.sharpziplib
4R76J5GDHSP5
MVYJRB0196R0
IBRFM77ECRZS
OfferInstaller global start
ARB7ICKNMVWU
Assembly Version
Problem in Download Json file directly
OfferInstaller global exception:
SPQQSZI0JE9T
72MYB211DLAZ
NNTE4SNGU5XG
AZ2JSNF07AZB
setup_id
-env=
9O8VUH87TSSW
Problem in DownloadAdvertiserInstallFile function, unable to download file, error:
CurrentUser
CCOC1C918NH6
7XAKLXOJEAUJ
CC87G6EFROK0
LZX9KBPNZBWH
ClassesRoot\
JXM6KERAI9DR
XF748P2W6C45
MZNZTMID7YNF
TNUQQJY8SWQM
GMJI8VG0UG2V
\Extracted
STUN0JZKAC59
8EZ92TRVJ54F
HEAFWRGC24AX
CurrentUser\
S1INP4K4RYEE
IH2JVZGMA3NV
DFP2E9LA8X0E
R6GE4X2AZH8V
X9QJB2WXH51S
97A2RO6JYBOP
7ZG6CSGLW1YZ
4BVMZL4DM51K
MY5690AC8A33
T5IZ9HJG9Z64
8SDF6LPLC5CB
&extra_params={0}&event={1}&sid=666&mac=777&adv_id={2}&biversion={3}
5JXT54HFCLFL
9HJL7WZ31KVW
7F2P8HKSY621
Problem in FillAdvertiserDetails function, error:
97XIPY21FLYV
U5V9R0AMLMX9
99TEIMVVHOIC
CGFBRG87JF9Q
JqBCdL
2&}ky
SWoZkB
DXMvVF
Oj{J
gKwkzY
NGQ,S
\EC\
CdVttl
bUseDirect
;"b?D
NpXjWD
{ q^
ZNKAMU
xDK-
ldWfcd
FjenXU
Um&?/o~g
Int32
2U<y
|TF;.
rUvpCN
&KDO
uHhOdT
7'Pa
"'\-}
g+X>8\
9`:~
5N;n
.[\ B),
Yr9B
6&Bf
ajcCmp
aqWT
BNOVaO
VxCxvR
&:O7
jG4|
ib0M
:LET
rf2ev
EQAkjq
Char
YAkGSi
tlTovn
%ao+
2Q[9
z'6
kbFCaa
AAjwTf
{}D9^1
i0)U
nCxlvL
Rbh+
uNVaak
TWp5
RCjSue
get_TwoLetterISOLanguageName
GpfXyD
_AfA
bX/o
)k~L
bbKw;
]p^tC
PZkHaP
DkXBtk
*K;u
+ r|
CEZdra
O%o
cYmlpD
gBl<
82O#
IWebProxy
DnU:
l|UZ
1Td:
Substring
[? |
t+|<
,Gzh
set_postInstallRegWrite
GS&/
/Q^cmq
Ksw<
G*e0
set_advID
aO+7
G i&
x!*V
B?mU
60ay6
16yO
b7c>
,)r
CFhOSq
K`cI
AsH]
rh.2KG~-
4KpO
YN5!>
/!%p
y$[>
15R
a,{ 6
qSYGmD
nuioZr
k',)B
xaCLVE
Y7G|
AQiiMW
x7u_
Culture
N!U9B
oDuvzE
jT RI
dRfpHF
YpshRc
qEJPwR
BwhHIO
gGgUrV
p=R
QCsnNd
*s{
_sUI~w
X|Bg
MPRQsq
bdvNBD
Rnc d
r"
yx(AQ
("y$
NJw/
=Cx_j_o
&Ie~
S3l
_y?u
QprXPH
vrfQKu
7kee
WqiQOg
HIpTxF
1j.Z
TEAbCP
RunInstallProcess
MKvWQ/ _
ufyiPv
POEQDS
f<h@N
igkDSu
gWifaZ
'm7id
b4H
j'mi
,:CZv
HeWZir
:5 p
+Tsmz
m_isAlreadyInstalled
1Gc>
,# o
12Sx4K
N1cx
v)\X
E-8r
.2f<
oneuBz
ewbdxT
W rn
r@$ L
!5,[
hYnIYJ
set_regKeysToCheck
cNDFck
rOoUbv
:dmw
%z5e
X#h4
]+Mn
hHUHCG
\%f^
set_minutesToSleepBeforeInstall
o/C\Mr
oceDGw
zUzauR
tHdnQc
%Nrg
N#s-
JdIr
MlfsNg
CvUdkf
kuR6
{b G
drLq3
(_
(]=,
7.c]
d,pt
OKNiQd
rc:O
,'r
mrlCkO
costura.newtonsoft.json.dll.zip
Srelao
u:IK
CZNVNs
evXMUU
ocMhFa
UcaLuV
I\ao
GKICAs
bBffuk
3Yy(1Fb/S
IEnumerator
#5g5
zcBirX
>I/f
mmj
U~%2
f`oI
v@ B
sFilesToCheck
;%8%
p\O2
/7B+
$[p
GMHI
TEcRjl
wGjRtU
%(HVT
".x7
RLMsBv
YkKMFu
jOu 6
4\;YqD
wjkzma
g2+1
F7EGLn
hZDyOn
*|CT
jlaYCx
<advID>k__BackingField
pbzTMW
CmAvdJ
YhDgiv
Exception
OHUBfr
zaQHDx
dOWYit
+g0.T6
L/f2
az5F
Hm B
S sXo
RJHmcE
'R.X>B<
/H"~
|1^I
*^=S
ZsoAxn
5{w{9
VICGuE
QK*6Q
NlKmHi
hz i
vAClOg
kplmCH
(cRFiF
Gh=?
WUDqjM
}k=/
-VmF
k z
iFuCEK
yIlL
ReportInstallStatus
$7M{S
kGVFlG
Z Kf
*}C8
{+\W}
pGp>
Format
|oA\
%_iF
-Tq0
>KF}m
:,z' 5
co~q
rjhSfl
RxdP$
Y{}6
@[#JkZye
ja~uy9
ReportUnSuccessfulJsonParse
x: V
qPPIIH
yKpJ
UAQfRL
(1K7
List`1
KD<K
u]<-
hmQ N
cTmOMf
AppDomain
G?o9
jlu vx
Vu-|x
SGSPtK
i)*
qH4w Q
fhagkl
:+Rj
'9Sx
jlg-
lOwWCi
aNIGah
U^'::
get_CurrentDomain
w'rZw
Exists
ip#?M
u+#
)2_v,%
Lrdnfv
5 YC
#Z+
Z=*w
q{3B
$x5^[
CO/^
]E:
= Q
jSlWqo
ci9G
zv[z?
e77
'| _;
J$]+
/[} XG~
IQs =
EvneMf
get_regKeysToCheck
~j/b
vV_r
SCzikz
OpenSubKey
IxZ"
ArrNQi
$'<]]
ZQk!
N;H=
g`jjU`T
k/w9
yuL
r* l|:
]4:
Dl(R
ZK2|
GetSystemDefaultBrowser
BzBiwV
DKRcna
"MJm5
T wn
necbtt
<'RR
NzJGfI
MJXsdH
yXuZ
t^z_
D}Fg
IstYpN
?=L>
&Bb*O
G[QK
4I<l
ZhPyPC
q&8w
5ew"
wjnyUx
hzkMTp
x!MUi
LrB7J
#YJa
XgWLly
f{A8
q $w3~:lcp7
oH
d.]"f
Mhke
~0 L
VB?
FUzXxe
X<Ca
Path
shofvX
,z+
AEyrZr
hFJlyN
ihCFOb
NfTMPQ
$UM5
$!3}
GetGeneralParams
% -
WefkwZ
SettingsBase
-)-;
Y?O6
'w%#
Lejgpe
W|x&rs
gIenaU
hhyiZl
<additionalFileCommandLine>k__BackingField
QUGZbY
i~%c
CGoNNn
j]([
- ~8
#Blob
PzncYd
dms"
AyuglH
{ HB
[S7t{}
~vV:
]/AU
CpU=n')
? }
FhODjT
f16Q
V%'@
Program
UKNz
lcTadD
fnRUkJ
5RzIv
dZbHTZ
HrXpqZ
sTXSUa
JaePvA
EtLFfg
xctOYb
ysfKYZ
XObWKX
| :U
mzbvJZ
YulXto
cWSJwb
nXeszc
grGlKK
2PQC
+;M@
bZ5Q}
iN p
1E3q0
BindingFlags
DuDXli
-`C}
Type
Z-Z&
G;uSUWx
E:k:
IkObpg
%2{g
qFktTZ
hsbZTu
![BP
d-HN
n]oz
=Ifb
wZeJuq
Mpezeh
bUpwya
X6@X
xEg"~6n
;L[4
System.Text
zi,
+$o=
ECAwaG
ssiZxT
XSfvLg
c/`g
*c{S
.|u@
CQakZz
ZsQJjv
XoeYXi
lKKDlA
{3DT{
ed`:2
Qdc=
hy9ei
;givoH
AKBiUw
PYGYPQ
Ifcueh
preInstallRegCheck
fPTmqP
LANqlq
U0!8
a9PG
Wnbtos
rDyqQV
%I-:Q
ICSharpCode.SharpZipLib.Zip
cTHnrh
*jOx
set_KeepAlive
qA%Z
S+jx
LYoOce
bEDDyz
RVzHJS
w9 \j
- 5B
|uXM9
ad i
zjNFks
L+4$?
Ol/x
XA-DN
ProcessModule
DDQd
SP3
khmupS
mCXF
~CuwC
)^bEZ0
@1]m
WS Z
sggvg
set_FileName
NZjStE
#p~P
Ils
iN71
{Mz
Zi%.4R"
? 0=
String
z/XG
*x(9
lqX,n
FjBGcH
&~Xn\
SEu[
cgXxMI
fU*A90|
|E4<?
w</K
tBvlTd
`W b
bsGRsV
3N^uE
Mu:M
HbOdTk
plahTZ
ToString
VD>9%5pD`|
'tc=^]
kEzbXA
>g d
v5TT-w
!h&j
SyAczu
0y+@
^otD
4d *Y5
\_E$(S
{d,.4R
0oha K
]j
PZKgSp
Al5b
Vt J
BLOCKED_EXISTS
eyfRUY
DOSAvD
+j q
affadn
9Fz*
1#TR
XgqFSR
+0rS
TEpuCh
dzGQeB
st(.
\0du
9\zr
hZbJYI
iAaWKF
Z! a
Version
-N'%B
m_av_list
v`/YS<! G
WrN3p
C%6G%>
XSV*
Hn\s#
?J"h&-c
fE9P
N2+m
OpenRead
<z1`m~F}
93%F
HxtEvM
RegistryKey
ekRxOt
9w?k_
PA
ox
beqcIp
)J3k
KWiDgv
nYfkQN
zmAScR
dwWiNx
$ST.o
'FD(.
@C'W
RzCbyj
RRVVkV
&G1T
bl6
qbVGNX
.text
/w@
VbbPTd
5Zn?r
s_[{
GetString
eECT
F'Fg
xDJJal
>r$}r
qvWnGV
YPVPyT
Ics&
hDSdlX
iNisMI
vRT9*
BogEKV
B-bW
GetDirectoryName
..q.
=z'z
D:S"
_`S
~ ]"
t Z[
kjlJnV
\5<]
ZUqrAd
zt [;
|Y~tT
hzgaFL
k$u}
hG'i|
6.p5
System.Configuration
<9,F
wbLxBX
SRQ'
orX?
entry
D rH
I'N0
bv#f
nnmxVo
&xGs%5zq
qybjtr
System.Reflection
||j
$t-A_
qOCHkN
:NlJi
B"t]
uuTnBx
1 -=
jdlOUf
JjFbxY
x*[}
jcFDHd
,eKT
Q1*r
X_-O
zA"w
wB '2
v`p?g
=&{$
NXYjo}O~
requireUnzip
2c1r
QJQEZh
iCbnfd
LGZCvo
E9%S
o
hM]9c
yiJDPS
z9s
yUzNSe
rxdCYM
S ]
zQCfbu
.l@\
R);9
BYn
fQrHhw
uDsp
LX5D
ZmNGtu
brEIzD
jbb?
q7.Z
rOgyQp
CreateDirectory
tloLzf
GeLdOF
Resources
w0NH
GD/q
BgN!
"(|
MlLeig
~Du/
<U`]
1]|.
{(4ctFJ
q4![
ocGWKz
mzm$
H 5,<
D_tS
Sp^:
xFBx
`P'l(
*E%@
mgQaae
ZnYebA
x[~4
Z _!
SngVmB
T41<6
NQvHzN
Nb@O
SPoNwa
XXUsT
]4}~
wwOiMF
YQN i
vrkFri
WaitForExit
-iOF
Ookwno
SX2\. _"
ZDywyr
9UK?M~9
p8'K
Z; !
D/Q"O
bXBGJF
-peR
Assembly
5 Z/
System.Net
twDqVM
nYqIWv
TQGY
Q<8d
56kl
Process
a&X#
Ahx
g| /'
@U75
ydeizW
=iho
`.rsrc
-Vr*
Ml-O
}-@_
C I!
iQDtwX
OygEk{
mX;ZG
/hz@
get_requireRegKeysCheck
EdvvEv
2:O0
)bc8y p
Gpfoym
get_Default
LpNofg
jvnqwk
8+ET
P~nw#{
Vg%V
MnMFSY
wSuspv
RA:V
i%{RIU
\=T7"ir&
dj4$
YWzqTz
B#N3
JI[
nFAwwg
ohw[
nZNwpD*+
set_Item
CLwirO
D~oH
DXfEgH
M#la
bFK>Z
Enumerator
fXyNmt
tAK7
pO;^
set_preInstallRegCheck
3zF%
fullname
bA2?
WcMxLR
I H*
'iY'4
B _5#k
umr]
e>HvjtD
ca%D
dSOM,
~=oS
U06o
additionalDelay
m,/r
4pg T
A7X J
9:Cnn;
lj\D
cQM(
r(cK
set_IsStreamOwner
DVHP
Settings
WU#b\
EjeVfu
mvrx_
+FMmf
G}g5Jr
FIkZsu
nse~
R0:i<
dfGGuV
k!v3(#
uV}c
}O
PSoQfy
ZipFile
9Dp<
epEPMU
LPchDM
KqdHtt
o1/GX
=",]
kM+H
>5Gh
GetCmdLineAsQueryParams
oogCda
NmUfXP
rIrBTl
MCCRaY
`/okn
1<J_4
secondaryOfferInstallPath
<FUQ5US
b}(\
<requireSuccessInstallCheck>k__BackingField
VfjNyh
8j8?
wAhcuY
p?R
|z[ff
AhiIIP
awyqJi
0*i6,
yhqFNK
u>|]
mePGRh
bHtLOG
PbS-a4
Fisfhr
1q:
'J6W+
S+y&
38VJ
:aC:G
H'fF
r"rcFd
LifUZX
%hMSL
:}c%
$o/*
])96
92`Z
HhOUOb
CGNkUs
ey)
eiS4For
#CJq
q[WC
]*+z
pPchiU
BH3
System.Net.Configuration
Gulufq
ASwVMU
=t}+
+ZR8
LpOFfA
t-@
DtxXfd
!/?,
NOtRZE
iCeRqw
:.:
hxldkG
10.0.0.0
ie]Z
k!q ;
-X'o
BU:S$j
["1;
ZzAPOB
STMFdI
$u#
YMdMlh
3nP=
FIVVog
K+(E
yP@Z
oRXOpo
GnaiDR
XO%(=)_
<SMG:sU St
Costura
sProxyIp
wMwLDm
%2H9
Advertiser
>H99{
Z'~0
wauUit
inwz
L U
KLHczQ
s*,>)p
get_ZipKey
Qe&w~
eJgUmt
Y{&K
NdzXlJ
/>sK
DownloadAdvertiserInstallFile
a+3v
Fhezln
Zya>
InstallAdditionalFile
q~*:
rFXxKd
li_&
chuX
weVS
kKuE
kMNmlF
[q Rf
MatchCollection
N%;vn'
B9'B
ihembT
3_sNO
<g)B|
FFMkb
Write
D_A>
AssemblyNameFlags
_TnO
,*-&
I|:2[9
vyPzYI
lziSLL
,m"R
bUUyop
LV-j
`0E:
GW).*
BCyZvJ
~lMN
vER6$
bUZ ?Fl
a:Rl[
,3VR
tzrv
downloadedSucceess
kv]]
#% a9
f>y
AUcOFt
1`o B^
MbVevD
x:V-
6d?;
N p\
>F<f
gy1Z5
QTQUxL
/r. 0
lq%7X}I
+7 *G
oujLwu
postInstallFiles
OgEiyS
oxPxJF
:-/Q<
G4W
+*qp
uZCXnS
bGW
<^ @
gWF=
r,"*5
KqiEqh
WmeDKu
BERnFW
Qpj
}1<k
%e8^
r71f\
(Ao$a
h:^+
UrpplP
2"Wi WQ
DIgfTQ
p&VvK
WDvWdm
EhMvqD
*G[g
pmBWut
UJ_^
TEa3
$-q*
x^|g
9l 8g
QGK}
mw}>
xHQ#_
JBQkfg
VnOe
ReplaceSpecialRegVals
oKNjLf
/ YhP
->(fvs
MJ|0
r(L
LfrY
!!tZ
u3A^QK
RTnMXy
e#_"
D ff%:9^
vMY[a
c%\>
QsjYnT
{)(\_
V? g
jSyPfV
PISXCb
}-Av
]GBr
nzTrvC
folderPath
OkCS
iVd+
hiRfWh
YfIYwe
LhnCYF
O"Km3
\'LW
u=?~
7L=$4k
QCHReO
UldFHE
J5D8
YasNsj
System.Globalization
SqQSFY
nXgklO
NrS-
h)A8oS
yEPq
;!GPAjfV
dMDgOy
EqLQ#
>MV]
chykK
vakj
STAThreadAttribute
7+ ~
g!^Ee
$595c8d31-df03-49b5-b724-3f1088ea433a
kzoR
mXZVCU
FS<w
BHEAdI
:G*g
m#/;+
ry4}
0~]R
oFrdJE
defaultInstance
sX6
O~?N
\u2n
op_Equality
X)pa
@7%>
b`OM
cs=mk
Egwcrk
E N
SPkqXM
q=ab
additionalFileCommandLine
<Eg1
f&prM
D= -e
Kt~i
P!wP\n
xPuxhX
GZMRBH
Ehc;Z
lR~E
$dQh
vIt7Dg &
ittmnh
BcsqYE
cfKxDt
-t))
FQzNcJ
heuBjk
mrzqUj
EVhecQ
/DpA
;8YG
JMQ
WUPjld
-%Oj~
`c*$
TG^v
System
hICUtp
C s -2
\5=DO
a \W
<?xml version="1.0" encoding="utf-8"?> <asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <!-- UAC Manifest Options If you want to change the Windows User Account Control level replace the requestedExecutionLevel node with one of the following. <requestedExecutionLevel level="asInvoker" uiAccess="false" /> <requestedExecutionLevel level="requireAdministrator" uiAccess="false" /> <requestedExecutionLevel level="highestAvailable" uiAccess="false" /> Specifying requestedExecutionLevel node will disable file and registry virtualization. If you want to utilize File and Registry Virtualization for backward compatibility then delete the requestedExecutionLevel node. --> <requestedExecutionLevel level="requireAdministrator" uiAccess="false" /> </requestedPrivileges> </security> </trustInfo> <compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"> <application> <!-- A list of all Windows versions that this application is designed to work with. Windows will automatically select the most compatible environment.--> <!-- If your application is designed to work with Windows vista, uncomment the following supportedOS node--> <supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/> <!-- If your application is designed to work with Windows 7, uncomment the following supportedOS node--> <supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/> <!-- If your application is designed to work with Windows 8, uncomment the following supportedOS node--> <supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/> </application> </compatibility> <!-- Enable themes for Windows common controls and dialogs (Windows XP and later) --> <!-- <dependency> <dependentAssembly> <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" /> </dependentAssembly> </dependency>--> </asmv1:assembly>
cyfGkz
HAoF
cLxkyV
xq#k
qbgLIJ
\40:B
vNMH'
dMJk<~
7CRX0
eqEwVS
Ix 'E
set_additionalFile
dMVIMO
s>_n3
$^qW
e?cU
EK6@
u|o4\
eYaeeu
ZYGYVI
T$Ny
+SX0t=:jsT
gSjBZd
Ah W
zjG;
m_biVersion
wlndzn
PropertyDataCollection
zkG?
GDYBeI
;N9=
CAVBAm
get_Name
GetArgValue
Y?I?
M6S"
3l*lT
v)o=
H.'|
"M*I
Yy3yJ
95Ou
D M
e}aa9
\|iO
f1o%
ClassesRoot
/,]h
vvlWLN
ciAFri
^ ?.
XuzZe
lGGcTp
M*H:;
bGa`j
Attach
#Strings
kueFWT
XeupFa
:?_joL
requireExitCodeCheck
System.Collections
HVcuiF
t/4#E
2$oB
$?=f
eM.k3
itYK
:H F:
3G+`
,^Aut
T>*:
pTL
/6^v
<oC\;
bN=K
'P@06
)9%T4
Capture
pr1I
jtRQFD
YQuSSS
fUJPzz
Zs dy
oDGJHR
5I<n
iDxj;
Up q
8B}B2
tempPath
{eSD+N
f~ z#
odluST
O,!G*9
reRMTk
fIGpLw
LxfJr|
StepitappLTD]?
T*jza
OwVbGv
preInstallRegKeys
<sga
0o2O
[|r|
Matches
*Vs
q~,lh
|Q[_
'sYZY
KpLUkb
+ 61
A'8$Nt8"*!
TU}e
)[nve
wcOTwJ
mBtmXk
- ;r
+9D9
mscoree.dll
y9z[
ZTRTCs
R6hW
lkAhYO
fuJrmw
@; z
#q` ]
L2 Y
BFR4
@M4z
[>|
LM+}
H.vs
O.OZ
RyckQi
bCnUdy
dgUy{
NSS~
%<$ K
D'ZLn
gUD|o
kruYFn
n~&v
<Attach>b__0
StartsWith
ZIsHul
KcIaBW
IP~~vV*N
JSdqeI
2Cvv
GyxARK
GetType
id1l
'Sn~
LkOcjY
]/ua
f]ip\-
add_AssemblyResolve
HuIUgq
[mMU
?$&x
uuAbtu
gazcYe
XHQiwx
get_GUID
qbUX
ZUJn}E
=:UV
tdGdjp
ND-E-C]
i^je<
s(
DeserializeObject
OiUMAq
\Ib6
TA^_9
DEbXJn
'@ o
8 s
yROhfm
R'WZ-rL
;Xg=a
" ey
X::`n
T"EB
~d\
\@N
? M#
BtVdtU
A%Hx#
<blockIfInstalled>k__BackingField
WQz
J*q2
W<s$
smQHfn
WJJyoM
#Hmi
RNC)
oSTXAn
YDxWsH
ljJSvY
) Oc
DKp*~
U`NhC
oLjmBO
lFs#
_>7tt
'RfA
5+gHQ
V6Mxo)o
xLbuRK
{cZ?
FgqNDx
sJd7) oW
TINELm
zhtnHZ
BB&3
TRBGNH
}46u
-i{Z
kGrvvT
BJQT
XhLpks
y#rk
*38K
i!O9WJ7
-Cr*
+HS=d
uD F
k>%1> B
hNPH
\_Vz
wSUCHu
XpconX
N"Pt;wA;u
@eA.
&O@wP\,
0 I3
DIuQ
97%3
wOXVlg
&]H^
}0EX
9vsn6;
NajJdG
@SEM
t[Qy
x]x!
1e~C
6] m
Y!QpD
tv =:
GV"=
,vPo
Wm~l
Z Y4T
{^6]uk
F rcb
SwNs
]-,C
4f):
ZGeLjn
(b1u[
updEBi
FileSystemInfo
Yxdy
^;&NM
acd18G
p'@f
GetValue
_M"I}W
rwdGPr
gOSRbJ
GetBytes
yjf 3
0 Cn*
]Ffg
ContainsKey
}hx>\W
CheckVirtual
Z<V[
jzonEm
vpiqKf
[mnQ
/8V9
UvBkvc
`K*m
qP]gu!I
8 t-p`
J4z[bO4j
xk\Jw
TtsZqI
^|Bd
s`7=M
sJ"RYB
kkuXGK
gWzBqg
vDRwbG
AssemblyProductAttribute
F {A
{euc
uOkPWp
yV=$
\%yE
S<f9C
ekiAlu
"ITM
OGzeUG
HeS,
nullCache
%eQn
vaIuTm
o'uR
$:6U
F;{J
QsyzjB
ManagementObject
zCKq
CopyTo
qt:z
8=O@
15[tf
''62E
{nY_
YaTCsn
GyCayf
MILl hh
MCVr4
hGPHFg
emS+
:qfK^
Q%K;
HTfwtV
VAOYxj
hRsIvS
TryParse
LIh"
RuntimeCompatibilityAttribute
.Z,?
%-<%
/(Dx
lNisiu
)x q
LpiQUn
1W#?
~-@<
O2Ak
Gw!-
e_gK
WG@|#C
qQwm>
j~&>
csGV
oaes"qp\!5
System.Management
`:Ei
OW/cJ-p
THAZpn
JO;N
cs[
rTjGDw
<preInstallFiles>k__BackingField
AUrocA
KeyValuePair`2
XtXqHY
|\}<s
TrimEnd
obEJoP
;- S
gTfZEd
jMjyPo
jqj3
V.X
o?%y
Q8I6hcKA
SQHtBe
8iB.
Io,~
Z#=F
aFJCaG
. 9Z
,;U7{p__*
#j0jt
]OwL
Z?u ..^x>
GetAssemblies
LDazuf
!Yg|
UQJHcJ
TKPeIM
Registry
m_pubID
Je6P
=AW#nK
Dr7'
T7G-Z
v6j;~
ZrC(
@w-s'lgt
)op]j'
mHHA*(
IcUGQJ
ZDjoTY
Y,H
uW3Q
EcZtwd
xdTvQx
pubID
zABwwI
oLPoWv
4wPk
DyfbOc
TkW,
zXxuvL
get_additionalFile
A6n5
Tqj
VDaWii
i*3U
o t1
TR7<O
oOqDRy
ChXGSz
>VR7
4Q&(v
GuidAttribute
AnxNtu
ZIyYXU
t; O
J| u.
VeoeVx
MSs5
EncryptMessage
DLjtew
D8X *
!;ORS
rGTFba
wQAkOq
sJ ~7
pGCQJG
qymh?
w_$66
FFrAI
IKqEqa
extraParams
[ <l
? x3
AssemblyCompanyAttribute
VoSjS
-m%flK
<55 F{
XXebmA
IHrltD
+=U=
j),$
T h0
sPqTME
CheckIfRegKeyExists
/j[Oj
KtLBGe
L.]o
`Y5}
LastIndexOf
DsH}
'QOJ
hXjr
c r`Hd
]C3a( `
1K;6
+7Qq
Bi@N
V N{
7:'7
<requireRegKeysCheck>k__BackingField
LjV"=
bIG2)7
veHTyn
InitArgs
Dt&Xi
?MCb
iX_Z
>:TPrn
gpJ?k
[ZX.
moctUc
ReferenceEquals
cuzFTP
s{D?w5
Default
DY/>
YcLS
ZC6h
p o%
pfpvev
B|EV
6`KM;pf
-8vA
IqbrPz
EHGRxa
IbDU
Byte
WfRBbi
zO7g
uqXoEU
S mW
o{^
@f{<
,5aWb
ycivBd
3{,<
At} d
[4EN}
4o$E {
^E^_
VZcekI
fw:+
tLCiXo
get_BI_Version
jg)V
hWSHNo
UoOuQk
<preInstallRegCheck>k__BackingField
Zg&? R
9<$3
JWVDqt
fk_R4
$v'}
'8r{
L"6)
mQv3
1e!
stream
DqUfwp
)P^Q
xoxE
7j9o
oxNSZd
Y;',
1qMK
l`Nm
(O&%9`
MdlCKh
t*q?
mLwufa
(Lt$
65kT
ziDqgG
XQDhtj
wOBn
v O$f
vpJDgI
hWvBAW
f?%d
$45T
vEWLRj
sUrl
brEqUP
sXl%
_R,)
OiQxZl
"F`4
MoveNext
D_1n
^},Y@
4qD
+hoM
zCEJYF
biWvYM
rmrBhd
OBgSKX
x| sz
znQQTm
PWoukS
CreateWebClientRequestUsingWebClient
product
peigjA
WSFL
"[M^@MF
[ -x
2xfz8
,]+l
C+K
bLjrmY
(rWh
jPKdq|mr
t\ y
]$+6V
a_J.V)
eNyY
p 2{
mkHtas
o]Ee|
GWPFwZ
@QRFk
FyVwBd
V.0)
PDzVyp
g"Zq:
95 N
FlOfxY
CS$<>9__CachedAnonymousMethodDelegate1
r v/'
^acUQ B
q%S}
X)"2^
PhQDRT
R 7t
x,Mo
SCv>
MrwYjN
.i,~
ReleaseMutex
rpnsOA
)!>,
FkV'
RCjqVe
|8Vn
U$DF
4bcq
hC,j2
81d)h
N^T_
N1=4*l
};Al
GetField
\hd?
tD5G)JY+J
5 4
uNTzVx
Ecrurs
Kohudb
8/"2
H?*|3
kgk_+
iZqj
'd.
)Rjk
21`&
Wi<-T
0 8L
QZExIF
dexygi
Flq Y
i8b&
K"Wz
B<aL
extractedFilePath
E2C=ml$
IPWEaS
3, 6D#
S{N1
~$*DV
6Yp7
. <7~
?9IomR
hnyXhK
z g{
nfUpVm
?,4f
dY/,
set_preInstallFiles
EObNZn
wpAytM
BsI7%
KTGzNp
'6zb
value__
7Jd~
wY>rE
GF(4U
+>
qCPcXy
i0zl }
?2*L
av{0
%sZ<
F[,r
2VJN
fPqmkq
TheUZQ
gBAyXk
CaoVUL
z@hvc%
set_Timeout
+iUyb
%;>;-
Environment
n\%gP
ADMCXI
T?Uu
olEvlh
:(MH
v- fI+
aSfNgS
P1C.
sk2O
mE9+
"U}/V=WR
:q1[>wm
?M)
MsBFpx
v%+-
9`T.
0d['
wkGEZu
=DK?
R7 ]i
RJWQoy
r| JcWzYK
FDNpgh
eventID
:{96)
domain
Move
jg3d%
SvQTqp
m_env
Q0)H
3System.Resources.Tools.StronglyTypedResourceBuilder
RQWWSM
];\@
<preInstallRequiredRegKeys>k__BackingField
x i
pspiNo
@d $
.1Sv
l0lJ]*
SkWjIf
/O#3
cybTy
GikPoE
R.+}l(
UBSska
;T)7
}4Hd
ZY\+
wWOaHB
RTcc
kBpUlm
mrZwmc
,G~
DMX9
RwBuTJ
[sy)
]|h'rE
]"#re
xlQkWB
8i!Wc
cGbrnk
_4ym3
buOlat
lM A
$gw,u
ImoDBf
4~K>
L8}A
WN#}
D\aw
iai]MX
sNVYgU
^9=s
|Nb$
\9A`
G:}R
set_postInstallFiles
+ii>
t2xX
Yjwe}/
AssemblyTitleAttribute
2*_H
"Yh+
e0(J
ke@UIz
UoaTEp
t&;o
:xc2
i|tq
OD-G]
)5?#
ijljhx
D4r,y
.cctor
;lqVv
gFPgGM
3Efs
&bd;v
@ZM*
kv:_(
DXtEdM
"R<L1$
OC%y
[Pvm?b1 R
YVeGAb
g0)%
Z `-
2O0 j>
U!\o
EATDBT
.A=+
yBTpMT
uv%c
get_requireSuccessInstallCheck
pSGtNz
lB|O
RAwBmW
"!QaA
sKey
PN\0
@|2:Aj
mfexlx
A"_y
g/NN
imsMzm
=K:Vfj)Kdv
IRDLrH
7 {h
-"I-W
JcRQlT
1k s
esmgbF
Y>!-
Combine
NujsYA
)x5(
%~KLp
!'l>
v&B\|
WdGjgD
CTJkCf
$y>'
/ wQ
wGNOYP
8Z lu
NCZbpY
AFy/
AOUqkH
p-wIt
6mL3Y
caVC
RsADyq
mQTBqz
AhnPuQ
,,T3
MGZ^
|O`O
vQxdEO
417=]
5J^p%o
{x"Q
OfferInstaller.Properties
RCZ:Z
V d%[
'J.?
p('"
ww5H
GR^c
GetFolderPath
3 ZI
DZ:&
RwyJXm
D Mi*
jn%
zN R
lcThQD
y>0J
WKz=v
5v5v
+qM\
(e1Hp
MF'r
cI_'
xgA_
RyEZbj
5<68
e\MnC;
*.O|%
acNOOB
.XDw
LadAqs
QLzVyW
CisqOj
`\hi(1
ResolveAssembly
K<2G
{;|0
lZ7m
$=yg
e\|Z
sPvoiG
rvgUah
uP/v
OZFy
<t<
>2P,
TDwtHb
<regKeysToCheck>k__BackingField
VhVC
Py#l
get_Message
efqwIh
ONN'
CPdjXg
>Z D
| 9c\P8kw
sBnNZF
28s$
S<YK
dKJv
iplTCX
uYptvW
AIAqeB
<postInstallFiles>k__BackingField
Um;7
{J!Z
xdud
r7te=
W'lC
filePath
Main
FrjORy
+0r_
av6|p[~
*D{z3
a'i
get_MainModule
Zue1i3A
1m8'
Cq~a
#Z R
P:j_ xD
iGVXtd
System.IO.Compression
4v#<
set_Method
cjEQWj
'f8]j
Y~vRa<i
!i/.
B{C
ZRpeFl
pathToAdvertiserDetailsDownload
<ix<
get_secondaryOfferInstallPath
CuEavg
C+ti
vgGHAV
z$v4
r {UD
set_primaryOfferInstallPath
M.J&q
CCoAuv
AssemblyLoader
c45FSM
P~7~
%8q# N
SqXect
`U\
wT'<
6cax
uOycpA
mOB4#}
tkaZKg
LYPlsp
;RlT
dqA&
mJxFnY
QD)[
TMcp
ROtW=
DklhKq
9nvUU
:!DR
-[wj]&d
Jv3K
IRuX\
m =z
[Q)[T
{ W8E
g"'pq
Fb>_M
`QVr
Array
a&1E
ORxKbr
'cEn
QysLjg
vNtyox
wyiAmo
,nf`8
`y`}5
%nZH
j$p7
r:MPn
_ fl
Y=hZE
dD v<
@.reloc
*.!8
yr=Dg
iruW&M
VdAUns
ProcessStartInfo
xmufuT
EVmDZx
n5p@
qUcmYw
ChtYKr
Ly?g
get_ExitCode
7d:u
qOIhtC
FZbXAO
RSSvpv
KmqUY
mTY:["
]}pS
tQNHhk
dgoxpr
sk^;
wKXiuV
7hJh
NsqcCG
sqocyH
(\la
STrbQL
bmPdSV
eD7U
s)@
pCMFVx
SpecialFolder
6 MDA
bdvCCS
RJruGl
fWmtkL
@M .
Load
C*[>gmB*[>g-#
wOyPpV
L'.t
get_constParams
2U%G
f{x%
^kh|
} {FN
ywSjHR
ebmAtq
g_reportPath
%.]E
sHPbPX
WCQ]
YgJSJt
NYHhnh
mlh+
WeNY
4ES.n
W0a_
pZEXSB
[fIiA
L 8S
.~4c
LwxtWp
aj0,R
^R C
/]o>
dteZvM
{\pH
mjkXuO
TFDQ
QY//}
]PLt
dghmnR
E+#]
~"4E
GetEnvironmentVariable
FJ6dK
p>UR
f]Bt5
lU/m
v k
TZnyck
IMkvRZ
dUNO
XSiAaO
\dz#T
EZYGYS
cgxQPa
R)~'
zhYkMh
NAjrxx
aYxcST
qoUcKi
kBaHrp
pF#v
@gis,
[Zq'
+ e\
oWyDws
BXwDLP
j:'^
OLiFxE
=AjA
q?=^D
u{o-
ihK
]CU[
ManagementObjectSearcher
M+1]
6|#N
~LZD
|RwZ9
Ohvxvl
+-r
~U#V]/
:GZZo
% M.'
=||`
oqIlcf
RSDSD
uAvjDT
d- e
okDuBH
~: [
DownloadAdvertiserAndInstall
r8z)
MemoryStream
h\L
AyeNZB
=HlNt8V
*8^k
:'<5
kPbXwB
^K})
az+TP
&@S.
"kdGd
ZWnaoL
8bZE
kvXxPh
<requireExitCodeCheck>k__BackingField
eKXNvp
2U)I
-Qb6
, r
lJtoRw
W0U
Directory
{@\s
H6-*
JcYUmJ
\2?~
75~q
Dwdnwj
[V/%F
xk ?
MPE@
sgh]K=
<]kR
3Sc,s
i-D<&+
jjFHzy
O,q0X
get_FullName
FILJZQ
&{eM
PGF(2
=tGxl=
OQ$e
2/27
cUjPbK
buH
get_Item
EMkIfb
BPYoMb
dAZfda
ICSharpCode.SharpZipLib.Core
installSuccess
)<Zl
9;sK
FileStream
ESkVwH
LLlv1\
7/Epa,{
Z4yl
+r58YQ
epPeJz
<primaryOfferInstallPath>k__BackingField
Ni>"
J|v`a
y~Dp=
SJqdTU
yFtELT
U-VfI
Z}S_
i61g
P :G
6CiI)*6V)
qhpcyj
$-=J}
lNSjkK
??~?*
qVvL\
>kgTT3O
PRuYYC
8;Aq
!yi&_
TTScBY
L,"x m;
*sML
P>[Q>[)
. 2r/UO
j Gv
VInQMV
NfD"
WWQcXw
)ci'
?<P }!
2`."
subMmu
xREghL
2{Ce
YAfS2
SbbhWM
/gPG
gqROtm
Q`VB
b x<
Srb@
Q.* ;
EKcXsr
zWH|
h %4
yTwhWz
Lhkczb
5C0aw
ltoOIM
FAIL
wWUdSc
NdZXLe
_ qGB
v8_#U
ryESaV
aTpElT
,q)^}>
XPGu
_-pVB
nMx!P
fNVydk
%dW%
emCcVW
p|Q
Dictionary`2
bliyMc
get_IsFile
lhXHXi
LCv|
(|`2
oHncjL
L#-s9H
WDManB
2CWE
BdUReq
lS;P
&H_i
ToCharArray
dK+
')=|
\TyD.g
-FCH 2
7hI J
GetInputStream
^Tu
Igyo
=\c ;:]
9$9+
i%,m=
_@F!
d2IR=
ub"c
g<)jV
U]nF
Z{u!
aguFZL
TVxNdH
QqcqLA
2Ce*
{yK^
ZzIMtf
,JD)
#uc
jKoDBE
LAwUGU
get_blockIfReqNotFount
set_constParams
%(aNeO~.
F(f/
DE(4Q_Y
>i;7Xr
E5Ro
wZGtfA
+G8<}
8?a]
Cs20
zni_+
UIbO
JNdvXbR
\"xJJS
VnfDkF
cVW1
/:Uf
Y}p
4l?Z
yb2j
sxiyJF
3w^7
ToLowerInvariant
uVqg
FqHdlZ
exitCode
.QI,
successExitCode
Fw'~
<successExitCode>k__BackingField
lgbHOY
0on%Bc
b Ai
[Am]u
prPPZG
>/'r6
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
'W_W
K(1c+
ucWxhw
yQjjPP
stAgxN
P.pD
4{E-r
:rfuz<
get_Version
DIHCvL
nji
0I eGh
e;#-/3$
& N&
KVIL
yIoDIG
v\GL&
)Cx!
xa9-r
n0~m
U$FX
Z3c"
fkmm
EXD}!
v%/5
CultureInfo
>fUc"
;Cf
gd04U
-Uai
set_regCheckDelay
9Dc!u
pynwTo
;~54
JloKri
)V= 6t
WebProxy
w'zO
&q{q
n`]h
mJmIqJ
VyL{
V8cw<
bpRtQf
.wB3k];/n
BI%]y
o*q(z
^:Xx
zT.~p
l`lQj
;;3^
>^E!
YHh=
sSYrI/-uH{
{&Z;
Wyni
ResourceManager
G0 L
06Ck
9[W>/
&GeF
/.vt
)_DS
set_requireExitCodeCheck
GetResponse
.w]O
zxYc
QQ]M
RemoveFromDic
-l[c8
}$[9
lFk}
!*]{~
TGbkVf
T@cC
5_ a
\KI>
g E(?G
ZxEstX
,>`c
dvl]Y
2v/x
o,1NR:
%Vgu;J
~R
870U*D
Zk)A
Y'-g
<)yy
*bb:
Copy
^aiHKy
ZebG(@
5f[>E %o
~c
~b
66A2l
6%L>/-
vmZLof
gpr/'
get_postInstallFiles
" \Vj
?3n&
JE=1
x6o5
1.r>
NsCdAH
7f QL
kwgvW
K0>.A
qMDM|
get_preInstallRegCheck
8&%W
yfOQEI
peQPdF
MV?A
.Wj0
U^[]_
ZIr7
yuhOIM
;4=^
]5/*\
, ~A
EuhX
bKOSPH
mgAkOr
U'`/
d. 5
]k]F o
{z]1nvknv+n
&H7j&8
U!Stm
l (7
W 3 R
' p<
cx0j
Qr!hG
! Y]
"\B+
j@h_
yXP,b=
J9~HQ
;!00%
QoI:eQ
AssemblyCopyrightAttribute
Se=}#
(riT
kXAdWu
L)@xK
5"3t
~g2~
mq4Jicw}
x\?-
RIxO
0&LK
minutesToSleepBeforeInstall
*VE{
]BBz
3ir~"r
HD5e
=|QTuc
Equals
?6,r
WaitOne
F /K
r@D?W
GunVwB
5p,p
A 'y
mNJ,
*GsR
f#u&
<additionalDelay>k__BackingField
4 9@
63(6n3
dai^[;
I[%A
MTNs
YVLBiK
eZpy
&*J?N
HQijir
;l9;
5wI^
lG7.
wDAVdX
R)K|
3&3OQ
K.Xg
#@? 4
B8SZ
l`d\
re:/
K{&A-
E H
XOgpvk
:?lIGf
A:~$
xiYqck
H9TJ
#`qt
vJ;B
F8]=
m=.o,)J
E`li
Xp9a
m_domain
hJVwLD
}YU2,
get_Keys
<Module>
XfdocG
%uhIU
9ZI.
1L+C
7VZ+
<>0HWd
Pj+d
0~G
C#}&
c;0
tUsaCV
Xr%U
?,mo
trjExo
ManagementObjectEnumerator
9B{2
=0WV
oNMwMr
h G;
E[<A
}J<-Dn
aHldOX
_^W`=
Smqw8
94g:
wTOoQs
;J^>'/
Jx~6
^y-_
5| z
m[@8
W:>Q
<constParams>k__BackingField
zAIzrg
kVXVrd
n(YjMdS
jk=;ok
v6'}
GUNNZp
GetSubKeyNames
VwNx
<:D[X
Uw~F
+1sH^N~
get_additionalDelay
~JoQNYoQ
t_Ut_
ra^H
CHvCYL
Jnkw
O ~/xN
>l@4
X9
^1'
3EHO&(
*qHg
=95{
YDTGwR
set_Arguments
ZJRilv
S^nF
`%(5
\Mz.
`!ZV
vWBUve
n0 it
U6p%
w)<-
V5J+
SUK>
n7F1
PHHBva
=27:7wv
Am@jjZm(
SQRHhB
O/D=E
primaryOfferInstallPath
' oE
74?V
xx}w
eLlt
~ a/
b{=:
ylLTKv
zCBoa
@}Ihv
,B~
ebLdyv
GErsHH
#O /
:V t
oNP?xx
B%wH
%zKO
offer_version
xEsKxt
'ASk
z p
j`9v
uDaI;m
preInstallFiles
c ,F
&)rl"
name
$k=pw
{` 2h
mscorlib
=]X4
DVlEys
V#?h
0$Vc
QYF3
sQ,~ao
`Pp[
{ERN
p}VG]
GrfmQQ
q{bcD
_i~e
)5tW
^ {5
eCbxnt
Refresh
FPrbvo
get_additionalFileCommandLine
gRZdKI
-l
d &[0
P<pl
iUeruP
<preInstallRegKeys>k__BackingField
A'^!Y
+% /x
P'I)m
S42Z
#u.J
M\,u
Oocoho
am5q
qb'q
utiQ
ReadFromEmbeddedResources
BKGNiA
B}z K
b{=K
1J'r
A=#z
sFOALS
R{a\1/
4Q[wz&
MeVB)
Guid
cFIzoH
pb>%/
OPknYv
(oB>E
[u]Fy
StreamUtils
vvFAvW
AVzSLO
xtxqjt
KkEoim
GetManifestResourceStream
48P5k@
57|X
ManagementBaseObject
IkdyBd
;DJb
_uXk|
S)b)C
nBsYHC
MHqWmP
A=["
x#YST
R4sy
E9^T
GS |
G_0d)
iV/M
-b>_
})h;
_Q"<
;VJ4r
n=4Z
E xQ
\ $^
CompilerGeneratedAttribute
.%a4
RuntimeTypeHandle
FfMFrB
!jm_
7^t
dZ\qT%
&ycH
"~SV
/I2z
L{/W
5y03up
})h_
?58Nkp
c jh{
/et$
XEtl
WKOvqp
1?=|
5KF<
7 r=L
/}b
J\dq!!:
?;/>
ov
#" \
bi_version
VVQGba
UKPCsw
HNQiV
ALREADY_EXISTS
5f B
2014
LICFwU
5Y%xx
Z#%<T%
fMiAnp
GCjyYd
~uDM
pbYqCe
zWd0&
smvsgx
_'~B
OtINMP
Xh^*
@?BC
Z6Ku7E
Append
*L f
t#-4
Args
b\P:
^kra
RBq
cRaKjp
regCheckDelay
[^G
QRZ`
_Aqs
X<,XMRR
qr{4<
nDExlF
?)F2
(Hk!A
sp
gwlg*D/
"F3]
kdcTTt
@JLP
nR=G)
JZ a
x#`z3g
destination
'Fk~
QkU5
Vnh0
A"eg
KzPpVZ
"[_)VZ
G()*
jTU3
`9A|[
wiuN
Delete
ehA%
H:Kbhl
nyX&
AssemblyDescriptionAttribute
`K;)[
s4/x
w7~Zg
}c9
4oIk\
qJ W
rs/O
IuaOsv
E $
?T$J
h ]
>1C8
p?7q
4}{)
.NE?"N
+,VT
>ZHY
zK,\
tjaADn
^=LE
j<.|e
pTBeFU
~N6vZT_
k#8Dp
set_Proxy
/4a:^
set_preInstallRequiredRegKeys
]bYHu
6p^
- r
9r?X
F,v#
`wj(|
'~G`H:
y~:n!
0TH9R
lI'N
H"G4
wf WL
nPRgMx
c /P
>50B
C<_Q'
N^c{E
AAz
IU ed
C6>}N
w*:X
S'Z.`
+>s \5J1
iQ>^
-KdZ
Ex5+
-"IW
b|"7+T#
)uU3`W?
Tf0Iy
+ *p
DeflateStream
( CP
1vCl
;<T h_2
set_requireUnzip
}bAwQ
ZuPWNW
a? w
'G-QhDl
]gj*
{${I
e,+
h [h
get_Assembly
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
get_Exists
0=^G
v0{)
r0Gl
zk47Z
'J#2
z2/'
$}JL
}H<6v
YqZCXv
cCvrrk
dFAg
)bn s
_B?3[
c[R,
7o&J
DO .
_$."
kZe?
!This program cannot be run in DOS mode. $
.$+I
RiRVF
y '3
9@)
File
bY%e
.An"
Cjve
6(to
costura.icsharpcode.sharpziplib.dll.zip
4R 4
YDW[
dnunmX
^VC;
L-=}
Dispose
xvHaBQ
fFrFn
k67z4&U
3\CQ
TwzRZo
/G%Fw
$=Ez:H
_*m3VZ
J49K
sWHy
GetCurrentProcess
UfzKki
>7=;
Z Iz
fG~L
`6o8`|
*"5
wVMW
FlH
Binder
kL],{B
System.Diagnostics
YWSi
U,^Y{
FillAdvertiserDetails
=#(D
wvtESY
2I[x5$
kde^
K n5!43
<3a
~*K>
pVLVoW
Bv(c
8gfZ3R
cWr2h
".8p
0I(c
wGXG
C3Bg
%r<\
) rs
RtlNAA
~c 8
OlknuGsG`M
#Vj!
x_ k
n=!9>
`y?=
IV.M.-.-TK
get_CultureInfo
tLCTrA
uiNk
E; P_
| @%t
O|kb
*muP
wqCupV
ihE#>
Ea._
}*y7
_RKj;e
{L?u=
h9X~;T3U'
fX=M
cw`nZJ
QBlw
get_CurrentCulture
E9;l
Sd 4"
2=rPNn
hPMJLn
"5i`w
<l.CX
xtp
4`*lv
%9~
e]=S
BSJB
tDqu
resourceCulture
/n3r
3e[jR
g9jCtN
t|Kt|
regKeysToCheck
8!qKp
K LKP
gOqOUT
Start
NRCnHz
h }W
aN;[
3KK_fJC
n6>l
,d o
h{l">Cg
W
/D2E
op_Inequality
JsonConvert
E+ f
ds,qf
kunT
assemblyNames
set_mappedParams
45&Y
\u7hr
get_minutesToSleepBeforeInstall
e O4
JF'F
([^T1C
Jf|.0Y2
RLtQLB
HttpWebRequest
i/N N
DXOB
bN`l
QVipzk
V ,3B
set_requireSuccessInstallCheck
iRam
fN`{l
H 5]
^!$@H
&&CNi
lOWu
_@oc
k'x7s)
&f>N&
Qeu/g
8|&w
! gp
At9E
> EP
:.:
Zm'l
aZDr{
iI'S
Tx[D
{poA
&.kSG
?+y<
<j"{
+e:za
T5[J
/4z_l
s+77
}Nry=
A5[=
Microsoft.Win32
~DYC
ZU@a
e2o;
e}%l
sP*N
sY9`>
uhtDef
Kf?f
b\A\k
I}~e
bnse
p"a:
xmsuOS
'1\R
%z;/
8IoZ
:{R2s
g> -
ksJ}
t!MD
ogal /
fVlFuJ
+7oT
ReadExistingAssembly
]2$
,RnDE
<[Uf
Q&1Ryw
]Ss55OS 4
iQKJKt
SUCCESS
symbolNames
pH$
N]Z[+gH
@8~
A+5h
[m`7
get_successExitCode
.;X0
16*6.vz
wUKst
GnDDhA
{&,jl
EditorBrowsableState
~P^8
xJ%H[
0z{U
1??E96
Q[wI
5I"gH2
x99G
preInstallRequiredRegKeys
lK:+
SiYS
@oJ"M
voIKrd
1Mw2
IimiNQ
R&j/cu
PF>
oU[J
v(-
Ya#*
+!YT
k{jt
set_preInstallRegKeys
:{WC
FwSq
}y[U
[jW+M
3sT1
c($sn9g
f6mn
<postInstallRegWrite>k__BackingField
Z^ $
dM9]Gq
wR>wX6
(7
8tDK(j4
x~us
finalFunc
3*yXy
(Bq7
[|"}
elgSUE
UK$t
, ~
1:>F*J
-!
PTeoLm
QCP3% x9`a^
2`?v
F;gY3\
Nw9&
xUoZmK
` L
Y/ O
P1k'(
"8Mp
(E+;E+
ER/&/:
X#l3T*
6sb&
pYv|y'
bAeTLU
*mplEj%
MOLg
hZ6t
>,1\
OGzmXt
,Z#+
zpx'
set_blockIfInstalled
PBumDU
VZ<?_-
+^uv
b^-G
la:5
,% ,"
o =B@l
@<%d
ta=
[+F+
requireRegKeysCheck
$n z
get_preInstallFiles
RWs;y
uWeQ}
(wTkO
PBC[
@MQs2c
Fa; 0}
f O?
J(7R
5I "h"
lqPJKz
jY>J
N^y{
.U#y=
gQ~@
Boolean
(L
(O
3 }}
$)* Bj
>\+
P]1I;
8u2+#
Yl6sJod
PADPADP1
WbV-A
yKyItk\
t<@.
gl$xN~
MmvQFF
IZkSQx
8b_]P
= %
127
LJh{
mHWs
&f.Jm
FileInfo
_=q)
ICSharpCode.SharpZipLib
2K4
g'D6
set_blockIfReqNotFount
parameters
1.0.0.1
StringComparison
{;NU-
^bnD5
CompilationRelaxationsAttribute
-- 7
vSX
babVbi
h}9
YGp@
>{}V
%hE*M}g
VyjtHx
/IA *H$
leGUqw
R=<'
o1Z)/
j/ j
9 IM
D<v;
9`fdW
xu53
ResolveEventArgs
6:E4
[SXK(
a~H|)
Uo+'/_3
%+ Nb
@Ce{
Fwlh
, r
0G!TKM
tXJDAm
*e'4
Mhtoar
BKyKqg
>F0tA
GEv!1
XRtgXU
g8z#
`/U]
flGomD
#VJx':L
cksIwp
|N2D
J6$-
L%X*
o9 F
uD*[h
M=Ef
BI_Version
V]LmZ
Q@n`
Create
mUOc
bVYXlk
culture
rkx{
,D~
<sl:
GsRXu
Y1(/+
zGjylw
uN t
jb<e
Tg>W
fKEM
<fVE
b*ZJ1
qAp?
HS!n
WpBVPx
{i{1
X+U#m
Close
sfD^*
" 5-
ag<B
iEvent
gH`H
VYFixW
wO aN
lN=GP
'Y u$
iKnl
L!NG
}{XwM
/)X|l`
U.=*
*NSK
jp# r
%`>
LD| G
}4wq
m<Lg_[
& DW
ResolveEventHandler
Ww1V
4.0.0.0
^W^Fq^-b1p
7| V
YniwRK
79 #
R?K5j
source
@o)J
QjuN}Z5TG
SzwffY
.q/9
+d.;
_ Y_C
;%8%
eHxM
O17:A
57l
0K}u
.='vb
set_UseShellExecute
pU"~
: kUNql5
'e8\
n~QDro~
byvkCf
9i,}
LYrC
z{3j
D@Zp
3k {*
requireSuccessInstallCheck
%_`fUw
)a:
"W/f
AssemblyName
aqRKbp
rhcjnz
ECZ"
!}S
XgZ?I
jjwM
OT1o
FV tii
AM|n
B"[m
System.IO
ML%v`
fs)fc
UXEJ
Ccz~
y/+
l Iyr(
DRd
2]+Z
R?%|
iVIwZr
NZ7#
TJM*
StringBuilder
vYXo
>X)8
%gF
D1> {
Ai
LHt
LnZLmX
setupID
H/bm1
E$ =
u7_P
h}w( I/
\C g
ZXqoVc
|V".
qPFN
NHo~@
E: Z
bD{>
]U_>An
CCXMBh
p :z
o@rO
+ GzJ2\
uOyZhr
yKSWfg
Mutex
h:>4Om
t <
set_requireRegKeysCheck
v@gB;
g_domain
| ]E
3V=t
BVU+
|~)b
zpkR
#lg=J7i
RY|7.
T~V~
0Jxj
8$_8
PropertyData
D'I
ygGnBQ
vhQsdk
u ;P
M'E
IaVyvP
4zbuT
ToBase64String
Z45SS1M
?5SG
M<P =m
xqRj
o-Vd[&
\7:U
jxWb
CRCu
2q]P
JwuUlX
DownloadFile
z{pu
%SJv
Rye}Y
,$~
oEibQx
@<&E
Gkz<
nRnwNW
?5A5
w$H&+
cZvlM~&
ReadStream
MP$x
,voz6
XkD2[
B;K2
Al?Q
/c(*%
~8n
co^E`
l!ag
GetName
x'!n
0WY/
(.^@
/ BS
q/ow!
HE/S
,,r
8OsO
O{">
T6Je
System.Resources
^m36&7
qzkpZR
]x2X
OfferInstaller.Properties.Resources.resources
$gJ!
>0OR
$d1K3
YxLDXY
BLHXqQ
dgc,
_B2l<3
jW=$
/= k{pW
UbifcW
![~3
T]WO
2D{2n
lI( =
a}TP
abCeuu
81MW
<4]x
{E;t
!mI+
"i83
clYwhj
ENn
DsxYiK
8n X
=mo(
tQrk
qV%mm
]Pa/SjI
,wIg
d V3
N!5kV
e39og
iNGbQd
E%jI
r)o6[
xizOUh
3" X
4I%i
EyfDTH
&AuE!
]/(m
4}^Y
+n?y
_bK
--}"
U /e
hx>\K
vGPXnL
IndexOf
W 80m
T49[
~@@>S
8RA=k
JtlnWn
c;,Cw7
g~1] 8
e,;V
q]~4
TStGWo
Oob%
?|>|
O6qt
wvIiBl
+Bwl
SetValue
j WX,
jnuE
tFDB
R=[#
;ZOrS
b[f8/S{[m
=*GR
gJ=*hrT8
[y|b
Encoding
' Y~
BmCqDX
$mChU
HirsBW
yvrTtx
j{? N
YM<{
C9<w
xpzj
FieldInfo
WaitHandle
O.qVaO,V
uKz?
|4q(
=3sy
l=Wq
#5)rC*P$
pnu(;Y
3EYg
e (+
WD!
GN]a
GetExecutingAssembly
Tsadht
bvSPch
Convert
pXWLjS
I?N\F
zc{+(
6XA3d;u
f9X'bW
awnkaq
oYNHgh
YnTeof
'-Z]
rJeRWP
get_blockIfInstalled
bsx!:
po oc'
NzjoC
CojgMB
CGfYES
)fIt
g;[|
DebuggerNonUserCodeAttribute
Z4]>
bEKBJy
Z*d
p ~{v
/OeX
>NaE
?ZgE
WebClient
#RB
l+R9i
j,A\l
&dIT%
Vj]-
`n^_
rQwKsV
N~[:
NWwI
'-?g
>%Vt
get_preInstallRequiredRegKeys
FKrgCf
VhABQA
<\aB
G(A|
xJYrQl
\1-~j_
)d,jH^naQrnQ!1'
SjQ^
J51w
.!Cf
JtK-4
uJGXQN
)$;+'
]?#~
AqUwAw
qH|L
%Gbz
oukzvc
.rr9
}TS^
>y0 t|
h ?N
i_df
Ynp"
Imx'
yHq1
w,Sb
>'4-
*k$1%Zz
Enum
,N~b
{ZTwZ
MGiwfL
W%z [
EditorBrowsableAttribute
<)W:e
czbvth
ctu (8I
z>6q>
2Yyk
m"h"tfV
HiqoiI
1#K
.zb
+9M1
& wx
dAm$
{z%26s8o$ 5+nD
ovjybd
x~U[<
Pnoqqs
FUjvtR
pisoRB
<additionalFile>k__BackingField
"-xf
^CI(
sW9.+
<Nb
bvlV^0]
MC{o
MZ m
v';Zg
ynfLET
ICoB
YeEOqS
91T=
qd,e
Match
#8-"
<G$N
gi1^
l!d ![
\(6Xt
ft#R
jKVSUj
5C1#
qMfddQ
>1.c
resourceMan
8sQK
N<]}5
z{xkk
zdkvWW
7\QO0
?~v.
h->_
QxNS
&}R"
W2VA
+1m.
zmtZQV
x1+{
8tz.
'AS
2]8l
SLmWXs
+hSZ
p~nO
4 8M
5zI]
ggviQU
{ 8K
ezM
rmg5
y^ M+
.K
GM#;Qo
ZtmyEC
CurrentUser
dk_"
`%( Dy0
QSxBev
DmTqZo
l2/&
|"XK
$# $
9"?JV"g
c~ZR
'=^[
SDpWjo
y9, @
ttXwyr
\X'c)
ProcessedByFody
V"-6
aI^O=FS
oKN5va
S O3V
m_advID
<cW/
izEYPP
|Mk$
QWqr
get_OSVersion
[ pu`
1Xdm
WD@_AxeE
S>:U\=
)h:o@<
{:YHW
nbIIBe
FAePap
EFAeuu
+xkmB<
CheckIfFilesExists
>/\- /
6+#+0
H/ 1#
O#DsQ
cePxJq
'>@f
EYIg
/uD7
-g ~
Reverse
B\xa
yQ*xP
]M$q
lo`k
HvD6
9Ga$
DirectoryInfo
wuNyfs
p (>
L.wFf
TryGetValue
=t@&
cBhUCB
}O\A
qn d
OnbJdw
Bc p
Ul|_*
ZvXVeg
j"xS$
\~ TeJ
]@?M
O0,pV
F\ X
QueryString
d6Id;
'.a;
<mappedParams>k__BackingField
2| [6
24:d
.bxX;
]P wF
(GBIb
& wd
gjvYKs
Newtonsoft.Json
I@_Pi
%y2 34
OfferInstaller_dotnet2.exe
mg0=
],WuNY
&n9
Nr0}
[Z2>
`}0>0
]K6&
kyzYjF
CC)M%
5B\!
FgpSE
VXkw
t'iV
NMlQ
n; S
z_o Q
yUB0i
wT!7
4^n-%
zcbz
|;i9n=
mTjmaM
&&?;4J
Object
:viJ
F;v>a
P/To
K~@"
^fm<
p?"}
3xf>
JI%S
ZlI1
N3Sv
n\f7
5/Uv
p2 I^
~O1{
ComVisibleAttribute
(wy{}}
EBlXpv
DZ?iY
get_Length
.@7/p@
>-}=GWQY
.ctor
By}O
set_Culture
mTe T
get_Value
mappedParams
"p)U
}mIC
mhTOhy
]j8
3T'J
assemblyName
kmIbVP
T|9`
]>p9
Bc7v
set_additionalFileCommandLine
dUZH
7V^2
I6L!!
*jnNq*
HNEogt
WriteSuccessReg
@oI!-
^d|p{9
|:bo
!^NZ
ednOrG
jCg K
R-gt|
{k8Z
i~b>
xLBYZk
u:C+KT
:VU3
1:XF
R?q?
?J./)
-b }~
MY;XO0
%k("
!w
wd.8
RDkZBP
$ gq
AssemblyConfigurationAttribute
<4')rzc!
4YV]
b 1];
@=g`
IzjPuT
KHhdxb
:z"!-
vMis
^J#u.f3
#v@(=
<"xZ
Y=G
get_Key
:=K7
K"A:
08y`
V"uS
E\H<
xXL=
63ei
n0a6|pR
ZipEntry
*zw-c
rVpCDB
Blaty
qERReQ
oKboMB
=Fw_
V' Z
dIyRZL
kwXMwC
*I_`
0MTtM
m_ur
}V y/zu&
XjJbuu
_CorExeMain
%Wu[
|V2z]
C?@i
1/{,J
<blockIfReqNotFount>k__BackingField
Z|HC
C2(v#
JsN
E@Y{
~
%) O
dsyBTe
#bm9
_) /
: 'n
Ec>dF
VyxA
fEFH
gGUadS
}Zk
x}mW
Stream
5(vW
hwdgVG
set_Position
iTcYqP
{M?Q}
dIyUs
pBYPhd
42kwN
|^jl
IsNullOrEmpty
gpO{
QVyCYr
^.[o
'RBc
fSNh
ZipKey
4xE)
\*@eb
VY2l
SqFyzm
@}Wm
34VYm5
>u.F
_Di.
p\|>*
"-$E
S+5_
LPSGaX
^ M 0
dO6A
)Y8D
LjEO'y
4>`L
mIsPOY
I/- 8Nq.gB
sKhn
m]Uw
C{#
ZN U
zy<I
:Lw
$C/;
InstallAdvertiserFile
System.Text.RegularExpressions
7OP~
|ib$
8Ij(A
eZ3q
GetAntiVirusInfoString
6=v1
9%j1
>>)"
tL+,
irsrYF
get_Culture
KcD2$
fO#9
4bTO
\_ oC
Contains
^*Zl
sA<N;
errorMsg
7Tyw
OtpEPH
*Ray
QLl:=
'/_#
6"e>
D>W
%/l;o
uHJfDD
qe6"
CreateInternalWebClientRequest
get_mappedParams
R,p#
#\0z*q q$:
W;ZI^
+T$Ny
kMSKUh
Ww @
sA
M3?
>ID>
7^,k^
WaD
h^]jk4
hoK>K
(,*r
cBfU [?
KDY^
kr{[
2.Co
_,fg
[8:z
RNQpSE
H$+&
# ,!
<b{
<regCheckDelay>k__BackingField
FtVDCs
0cp%\[s]
$kNGY0c
j{_A^
j5SxF
nR_
U#{D
Uq$kH
o?s{
RYpWMP
=?@_
Kpt/,Ipt7
R^n\
g!%S
OperatingSystem
Wi>5
_;]
BP_U
d.(&
xyPY9 M
WrapNonExceptionThrows
wa43y
bWlXBo
_#nW
q=VX
XOYNjG
2-
Regex
Mcxl
I2OFw
e2oo.
get_Flags
&|e
Y+ NT
uh`*b
9 ($w
45NS
@ -6
<pn"
Bk8I.
i-4e\
System.Threading
RZMJxj
omlcsA
$WGv+
rvRhhc
WQaGXp
6KN n
kQ@H
o qO
&VxO,kE
!)af
FKs
+GoQ
qo{A
</'-
NbbZLP
^PJ^
8im#bdm
%R7l
p[ n
-qqW
au?5
UD[h
um4%#
E)=Y
i\`J
-~E}
UGTYdD
>uuz
;r!g!
K~`1#o
hc;:
=0l\"
BnGPae
9LlJ
lHE
o8{o
Al+|
m>MeW
oHzLyK
E;(KN
n1 }9 r
System.CodeDom.Compiler
*V(c
k?9U
)}.t
B4j+
XHUJbr
?EqR
,j+y
Gbbwoe
%6 cK
o(_}
x#;a
Ddz.
@kTbp
_D<*8W
1=vm
A[W/tgt
Krn[Jn2GE
b_4mo)
J',{%|
CreateWebClientRequest
&|4<
RSKGzO
u!_-|
VeOMUR
yy xyc<N
rM3!
JOt
ky<=
advID
dY6w
>Ut$$
#mWZ
l/7v
LF>Y
U 4vb
}1a?/
ZnQZVE
Z \M
':eG
^}tli4
U=0F
antivirusList
MK=M
O5^tDW
"fgKX
j{?
B1%9b
set_StartInfo
vduyLa
*|D6
sCj^
Fstcxq
-`
InvokeMember
0GUO
IU*~C
J"GA3cQ@
x~UK
,}wo
I/ s
E[/?
V E'SMg
_]gt
$! E
|=8A
,voe
+g^
euln
get_regCheckDelay
get_Minor
> [>
EndsWith
nwZgZy
Q`/0 L
J<?G{
4{96h
vCWB
aZm
kTwwYR
'q:E
94FS
UVblgA
}4A4
+:
,;>'
Y ^r
7V2+
'E ~
pUf
1dI4
zB#/
{^/af
+$
NNUW
^04
A8V
HATe
+.
hm (bzo
}XS!
|IW$
ReportUnSuccessfulDownload
JVy/%
T{^#
Copyright
[0z
X;4J
get_ResourceManager
8VpV
@@r])
Ctjtb
w. }
fTeJ=$
0=X:
[ ?
3 7G
%Ui(
j0pR
+J
faO;
OcAg)
$6db>EMAI
v9Nn{>-
55ES
sL}E[X
b4[i
~AF
get_requireUnzip
/ySc3wN
n)$e
EIthXB
A'@n6m
BgJ
set_successExitCode
v2.0.50727
[R&P(
1[wv
msRR
Ge=ly
8_la
l/ \
resourceNames
9:';
<secondaryOfferInstallPath>k__BackingField
nXOmFl
9(Ek
zjXJfH
H M$
r-.D-.B
:!\E
dj8Ya:R!:R
hj{M
huCwkk
GXxXBC
M2~y4Q
fpsNPE
s%St
Z]J=
[v"
uzpNpX
Pa j*
additionalFile
0JR8
BQpXkD
^k(^
I=:
IDisposable
K[5e
?[Fi7L
a{$%
wFzL^G=
CrCAiK
SmcMI
tXzxv
2.Ns
O LU?
;GPDU-
%wMH
\u]{
I]p O
(xf:
/EKw
t}o+
juS<w
get_Properties
> IU
{gP<
C:7@:}!
#~|ew
=CH&o
`|"}
JLIIUB
get_ASCII
3^ O
$9$+K
3LRx
J`8v
RrIH
>nc,;
w`'z
gs ,W(
7O"b
IJIE$MK<*h
dx*8
:/"P\
f X\
O!We
zZJ:8M
f6D
Kr e
*n! 9
get_Major
_regKeysToCheck
rU_@
GetEnumerator
er=/?
Installer
1:vf
~R
W}!O
7:!
ED'=Z
Jgt
v,fbO
w( ~
hkgDTv
b~?z
$Hb[9^x
EwHE
JPjjXt
QMyi
ndLecR
Oicgxe
IuAM
QxfEda
(E\n
tAO!
j,[/S
PNhC
[=koP
(72!
G]Qf
O21:
*A$.
_ @x\
Z!o(
~b
~c
* (#
tHI0Hp;
:zll.j
$J$ cSd
z?":X
.\b
i1UK1
~
NqkdFE
DBqbUy
v5<.
[Nn0m
:p'=
oBoiai
x%Zn#G
A;Kh-A=
A4s)
:CSgjj
8q Z
x_9>d
get_advID
)]MJC
`w50
GTYFBH
oUhcNt
Go(9l
Wnq}
ndf[X' Z
0 P2
ETwPjp
ReportError
SUTta
_itx`q'
d.W22
r8j7
eYPhlO
Qu6_
|]gh
fZ#o
% TW
[EKc?|
oz-b
xbvdGe
{@w)
_i!q
OfferInstaller
fL0[
text
?j|@i3
System.Runtime.InteropServices
#t_W8
bJbd
& ow
cJ@&
u"7\
GsRqcr
GetAntiVirusInfo
!~ /A
UnsafeHeaderParsingAllow
UK8m7
Aw1#
`cp/<{ a:
~?al
kdwRFE
E (*@
$Wpa
/?i^
^:P>
tMsqWM
g H
j6>G
+G~
VeG!
oVsGTG
o
cu%P0
hlL*
OfferInstaller_dotnet2
FdK>
SE-D
`X
VyV7
aayK
OKkGTa
System.Runtime.CompilerServices
~H*=
p+Kl&6
$r<g
30b]
c+^B
irjUgt
R7:HXO
<minutesToSleepBeforeInstall>k__BackingField
d1m
w 79zb
o1@>
72Y6
D|]OZ
I]gSI
v4k
VR9-{W
.k<3$
D1~s
xF':_
,Bl2
'U.At
9hG_
!e:N
!%;K
_!nt
kF}J
<(CFe
,
; {JI
d |p
yxykca
(L<d
;/3:
gnJ]
T }L#^
Tj 92
R~F
NNA>
@^8-
dPKa
NY|K;
9,=?
vc"
l8U1
5* d
set_ExitCode
s. M
9>OJ
$?gC!
E }-A8
\7P1
zXS9Z
5k T
1w7(^=
Mx_D
V/]l
TH{V
I\g~
V?Fz
'"GZ~
<:],+-x
CSRaAl
sX<L
T);1
;C\a
Q?t+h
lzRqDt
1-Du
lPp&
MO:S
+> >K
mEgjT
YGSNO
x#WD
m>[SB
zG(-
B H[ !
xIRgMV
gr.b
%*H]
R\+uA@
$]B*
)K%E
W|A
JWkt
FsSa-
pznkza
Synchronized
MnB~
WAoE
1 _d
$:ytVNqNPv~f
{o6s
0gL
b|x2
get_Current
k;]e
_S+4u
CreateSubKey
vsEQfO
YrsJ
H \A
iYuWul
bZ4,O
p`u$`(
tUS?
uPyNbH
)]GHC
CompressionMode
Q<X~>
0:D5x
get_requireExitCodeCheck
A~VY5
8v1S6
yy8N
PQENZG
O R
-) rN
UZE_
args
BiMRZ
U> ]
ZBlDFB
lHhJNi
yXmLVC
{zh/
TQ$'
D~@4
3cWWB
,a<
zFdenC
&K:
DownloadString
Z] h
\%vi
ST@R
Q:T-
set_secondaryOfferInstallPath
z&L[
#1.YM
Kf`K
Te U
RQISOh
0=4I
/GP8
RenameFileAndUnzip
G ?]J
?9-;
\7t
#&M;
QX\T,
fT.!W}%s
} b)
jFfE
lZ|+k
value
!< u
JW2
Af =V]
MPxRzf
BC;q
}H85
DownloadAdditionalFile
;aYBvEeL ]W
EW E
! YEi
`_W=
&rRz
2Vr~
8(#'
]s1X
w>2t^
x.]DPE
jK:%
|$qJ3
ank1
Init
5%~
krbqLR
Y>'9
dySNz<
V|::/
Fa0i)
u}V;
AnbyZR
k)-&
!Q26
X? y
[-~;
<{?u\
KeyCollection
JeQiXi
6=Bp
*~
j#p]
i0X2
0 (A
1thT~
<oK9
t?Ug
AMqoYg
?+7-oT
J6M!
postInstallRegWrite
#GUID
!Cin$
3+s^
OJX~N
Otb|
EcaLip
Dbfvfw
G+ih(_
RZV;
)WFH
uHPvFr
SettingsSection
I|Tr
LdRDj
4->[
\oS{
THgiqY
vAqW
PropertyDataEnumerator
=kVb
5*>w
pAeQvC
Read
q>`it
|/M7
?}]
vqEjKV
SA+a
rTokyO
HUSH^v6t
; 5w
u #
CultureToString
Wr:;d
97C4
v'3]
nh6
)fL',U
vX?d{
jZ7p
}p_%
.SB^
wFOucI
JDTB
0"@
TAXsh
get_preInstallRegKeys
K'M}j
7+_
Wi2z^*m
,xEe3
ApplicationSettingsBase
~tdx
cZ{WI
%jZ"
j5Yxj
Jwe?
9H^-q^
P)f&B
5?TX,
ath)
KyWXYC
V5|#
Mld6\
t"c!
wE(
J{E
AwWT
z<|(
^T5l
CUxLWe
iByxCk
pT+ 8
!7iz
NB|J
QnVdoK
Thread
?DR)m
ym6`
x95pj
L IY
:XhV
;]6_
DEQP<
.54K
8C
%0x/y@
_4~/*
l %
'q90Y*
R7\/3
)^{5
i^r0
Cpaqfl
#2|f
B _V
Y[V[
<`l^
}L M
+iA}
DOsZ
S<yoJ
Q.@
k p
MbymtT
L+MS
UyhPFz
#<F{L
8+ u
@ ax
W8 *
h}uh
DIfg7%+f
M`U@
<))]u
UrCGLj
WebResponse
C].y
fI-\
m!m[
9O$S
P*S4|
constParams
.'`wx(
4v_k
J'P"
zBwxDd
r!!7
mCQkgJ
EhyebM
,ZVA
%b!:_
c~yQ
c:s~
N(0?
blockIfReqNotFount
"~Me
J^Td+t!
]*hj
BExygW
tjdsZG
|~># R'
7Qz6
b_r-
GetTypeFromHandle
g!1c
2[ K
9Wyfu^w
'E:L
:&R4|
7{|:
OurtiD
GetAssembly
6YI-_'
o'G<
b[o[h
,)L3
iYGiYGi
z<Q~
rpmjjw
N BO
TBSIM
N%?}F
ToLower
UK5&R!
^EXM
JXvD
m_isRequiredRegFound
Replace
System.ComponentModel
u{&6|y
LocalMachine
AssemblyTrademarkAttribute
fYQ'4<
requestedAssemblyName
ihgSdZ
VWMVqT
~C20
\[{3
ManagementObjectCollection
,KW:y
blockIfInstalled
asvTct
], bG@
>C5(<0
/E{f
K >Z
Ohjhjy
mfRhNJ
set_DefaultWebProxy
IrC:
XxK
i4h$
P7eJ
?%Xk
E]-t
{D#)?\
;1K`6:
&G ys
*&G
'sO4
dN,f
CreateWebClientRequestUsingWebRequest
4_>^_
ug*2a,uo
wEz$
D[V
WebRequest
C! (
d%&&YN
zJkf
JsFHZL
}R)m
DDJQzo
QvyYJ
Ax] b
^-P+
iYGiYGiYG
c"u=
g;g q
D3~au
R96"r o
`:d6
z;iK
KfmQDC
2>[b
installParams
System.Collections.Generic
UHm0j
G<p|
H$ $
YTrDYO
$jHT
ExitCodes
s^;k
D|L K
o7 <
GJhVCr
fqfb
CCNjSC
=4{njanV
Zhx5
AssemblyFileVersionAttribute
uOSjac
d+ef
{VZ=
Concat
|4+NP
`wa
Cd6,
. 8
1* CZ
&0:o
qT;))
|5Vp.
}G*m
k5v2
lO_5
w_B~O)
1Y~)
!;.'
set_additionalDelay
aAijtK
LoadStream
*,m
MrbCTT
[tNOfz.e2i
0VI
26M\
":R&
G \l1
Tl0
r8;0
],x5
u/i-<
l#0'
20i8
Empty
*@UO
Z1M=pZ
\Wh]
1]xm
set_Password
GeneratedCodeAttribute
J>+xl`9
wI%$
get_primaryOfferInstallPath
8<JOpM6
tYLq
J#rF
Remove
'9Ls
ESZTo
w |Y
jLjHuA
Cg9>
:o;x
V0w2
TSr.
NxIa
:I3
T:^#Wz
h*,d$
UD4+
`5.g
get_postInstallRegWrite
\:SajA
:%,D
D|N{
Sg ^hx
M eg
!ms`
|ME~
yD=e
gTDBWC
Sleep
Z4Ay/
A6fF
0;oi8
l{'p
G.<Ra
Jt>1j
hJettT
<requireUnzip>k__BackingField
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03_64 Seven03_64 VirtualBox 2017-04-11 14:06:07 2017-04-11 14:08:58 171

7 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03_64 Seven03_64 VirtualBox 2017-04-11 14:06:07 2017-04-11 14:08:58 171

10 Summary items with data

Files

C:\Windows\sysnative\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework64\*
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\OfferInstaller_dotnet2.exe.config
C:\Users\Seven01\AppData\Local\Temp\OfferInstaller_dotnet2.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\sysnative\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\sysnative\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\sysnative\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\OfferInstaller_dotnet2.exe.Local\
C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_88dcc0bf2fb1b808
C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_88dcc0bf2fb1b808\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework64\v4.0.30319
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_64\index148.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9469491f37d9c35b596968b206615309\mscorlib.ni.dll
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\OfferInstaller_dotnet2.config
C:\Users\Seven01\AppData\Local\Temp\OfferInstaller_dotnet2.INI
C:\Windows\sysnative\l_intl.nls
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_64\System\adff7dd9fe8e541775c46b6363401b22\System.ni.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Seven01\AppData\Local\Temp\it-IT\OfferInstaller_dotnet2.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\OfferInstaller_dotnet2.resources\OfferInstaller_dotnet2.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\OfferInstaller_dotnet2.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\OfferInstaller_dotnet2.resources\OfferInstaller_dotnet2.resources.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\OfferInstaller_dotnet2.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\OfferInstaller_dotnet2.resources\OfferInstaller_dotnet2.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\OfferInstaller_dotnet2.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\OfferInstaller_dotnet2.resources\OfferInstaller_dotnet2.resources.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\091b931d0f6408001747dbbbb05dbe66\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\ee795155543768ea67eecddc686a1e9e\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\Globalization\en.nlp
C:\Windows\sysnative\tzres.dll
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_64\System.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\System.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources\System.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources\System.resources.exe
C:\Windows\assembly\GAC_64\System.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c44929bde355680c886f8a52f5e22b81\System.Management.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\OLEAUT32.dll
C:\Windows\assembly\GAC_64\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_64\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch.2296.19254921
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.2296.19254921
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch.2296.19254953
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\PIPE\samr
C:\DosDevices\pipe\
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Windows\Globalization\Sorting\sortdefault.nls
\??\WMIDataDevice
\??\PIPE\lsarpc
\??\PIPE\srvsvc
C:\Windows\sysnative\OemInfo.Ini
C:\Windows\sysnative\OemLogo.Bmp

Read Files

C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\OfferInstaller_dotnet2.exe.config
C:\Users\Seven01\AppData\Local\Temp\OfferInstaller_dotnet2.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_88dcc0bf2fb1b808\msvcr80.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_64\index148.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9469491f37d9c35b596968b206615309\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\sysnative\l_intl.nls
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\System\adff7dd9fe8e541775c46b6363401b22\System.ni.dll
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\091b931d0f6408001747dbbbb05dbe66\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\ee795155543768ea67eecddc686a1e9e\System.Xml.ni.dll
C:\Windows\sysnative\tzres.dll
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c44929bde355680c886f8a52f5e22b81\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Windows\Globalization\Sorting\sortdefault.nls
\??\WMIDataDevice
\??\PIPE\lsarpc
\??\PIPE\srvsvc
C:\Windows\sysnative\OemInfo.Ini
C:\Windows\sysnative\OemLogo.Bmp

Write Files

\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\WMIDataDevice
\??\PIPE\lsarpc
\??\PIPE\srvsvc

Delete Files

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch.2296.19254921
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.2296.19254921
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch.2296.19254953

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OfferInstaller_dotnet2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,AMD64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\547c852c\54982129
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CseOn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TailCallOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeInline
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeCalliOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NewGCCalc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TURNOFFDEBUGINFO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableHotCold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\internal\jit\Perf
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\78aff4c3\31122f2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|OfferInstaller_dotnet2.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|OfferInstaller_dotnet2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|OfferInstaller_dotnet2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\78aff4c3\37205d0c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\433351e7\2db83a0b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\433351e7\26b4a30
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\OfferInstaller_dotnet2.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6620029D
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Clients\StartMenuInternet
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_LOCAL_MACHINE\HARDWARE\ACPI\FADT
HKEY_LOCAL_MACHINE\HARDWARE\ACPI\FADT\VBOX__
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{5F6D61D9-D207-449A-BD48-652A5D1F25BE}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{E43D242B-9EAB-4626-A952-46649FBB939A}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANBH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIPV6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\MEMORY MANAGEMENT\PagingFiles
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TimeZoneInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\DisableAutoDaylightTimeSet
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CrashControl\AutoReboot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
HKEY_LOCAL_MACHINE\HARDWARE\Description\System
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\Identifier

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,AMD64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CseOn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TailCallOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeInline
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeCalliOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NewGCCalc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TURNOFFDEBUGINFO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableHotCold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6620029D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1974C121-0FC8-4703-ACDD-5DDAE1ACCBFB}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3E5B7CCF-3310-4B3A-876C-0804FC7A7AD6}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DC5AEDFB-01A4-4717-A63B-8C99E902A0E6}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{DE82A22B-8AB8-4C2E-9504-96D7827F2A5B}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\MEMORY MANAGEMENT\PagingFiles
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\DisableAutoDaylightTimeSet
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CrashControl\AutoReboot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\Identifier

Write Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfferInstaller_dotnet2_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
Global\.net clr networking

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlVirtualUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.GlobalMemoryStatusEx
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
ole32.dll.CoGetContextToken
kernel32.dll.GetFullPathNameW
kernel32.dll.GetVersionExW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.CreateEventW
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcess
kernel32.dll.CreateFileW
kernel32.dll.GetFileType
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
rasapi32.dll.RasEnumConnectionsW
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
kernel32.dll.GetCurrentProcessId
kernel32.dll.GetComputerNameW
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.LocalFree
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.UnmapViewOfFile
kernel32.dll.VirtualQuery
kernel32.dll.ReleaseMutex
advapi32.dll.CreateWellKnownSid
kernel32.dll.CreateMutexW
kernel32.dll.WaitForSingleObject
kernel32.dll.OpenMutexW
kernel32.dll.OpenProcess
kernel32.dll.GetProcessTimes
ws2_32.dll.WSAIoctl
kernel32.dll.FormatMessageW
rasapi32.dll.RasConnectionNotificationW
advapi32.dll.RegOpenCurrentUser
advapi32.dll.RegNotifyChangeKeyValue
sechost.dll.NotifyServiceStatusChangeA
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
kernel32.dll.SetEvent
kernel32.dll.ResetEvent
kernel32.dll.GetACP
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
kernel32.dll.LocalAlloc
ws2_32.dll.inet_addr
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
ws2_32.dll.WSAConnect
ws2_32.dll.send
ws2_32.dll.recv
ws2_32.dll.shutdown
kernel32.dll.GetEnvironmentVariableW
advapi32.dll.LookupPrivilegeValueW
advapi32.dll.AdjustTokenPrivileges
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
ole32.dll.CoWaitForMultipleHandles
sechost.dll.LookupAccountNameLocalW
ole32.dll.IIDFromString
ole32.dll.CoGetClassObject
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptAcquireContextW
ole32.dll.CoCreateFreeThreadedMarshaler
ole32.dll.CoGetObjectContext
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
oleaut32.dll.#2
oleaut32.dll.#6
kernel32.dll.LoadLibraryA
kernel32.dll.GetProcAddress
wminet_utils.dll.ResetSecurity
wminet_utils.dll.SetSecurity
wminet_utils.dll.BlessIWbemServices
wminet_utils.dll.BlessIWbemServicesObject
wminet_utils.dll.GetPropertyHandle
wminet_utils.dll.WritePropertyValue
wminet_utils.dll.Clone
wminet_utils.dll.VerifyClientKey
wminet_utils.dll.GetQualifierSet
wminet_utils.dll.Get
wminet_utils.dll.Put
wminet_utils.dll.Delete
wminet_utils.dll.GetNames
wminet_utils.dll.BeginEnumeration
wminet_utils.dll.Next
wminet_utils.dll.EndEnumeration
wminet_utils.dll.GetPropertyQualifierSet
wminet_utils.dll.GetObjectText
wminet_utils.dll.SpawnDerivedClass
wminet_utils.dll.SpawnInstance
wminet_utils.dll.CompareTo
wminet_utils.dll.GetPropertyOrigin
wminet_utils.dll.InheritsFrom
wminet_utils.dll.GetMethod
wminet_utils.dll.PutMethod
wminet_utils.dll.DeleteMethod
wminet_utils.dll.BeginMethodEnumeration
wminet_utils.dll.NextMethod
wminet_utils.dll.EndMethodEnumeration
wminet_utils.dll.GetMethodQualifierSet
wminet_utils.dll.GetMethodOrigin
wminet_utils.dll.QualifierSet_Get
wminet_utils.dll.QualifierSet_Put
wminet_utils.dll.QualifierSet_Delete
wminet_utils.dll.QualifierSet_GetNames
wminet_utils.dll.QualifierSet_BeginEnumeration
wminet_utils.dll.QualifierSet_Next
wminet_utils.dll.QualifierSet_EndEnumeration
wminet_utils.dll.GetCurrentApartmentType
wminet_utils.dll.GetDemultiplexedStub
wminet_utils.dll.CreateInstanceEnumWmi
wminet_utils.dll.CreateClassEnumWmi
wminet_utils.dll.ExecQueryWmi
wminet_utils.dll.ExecNotificationQueryWmi
wminet_utils.dll.PutInstanceWmi
wminet_utils.dll.PutClassWmi
wminet_utils.dll.CloneEnumWbemClassObject
wminet_utils.dll.ConnectServerWmi
oleaut32.dll.SysAllocStringLen
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
oleaut32.dll.SysFreeString
ole32.dll.CoUninitialize
oleaut32.dll.#500
oleaut32.dll.SysStringLen
kernel32.dll.RtlZeroMemory
oleaut32.dll.#283
oleaut32.dll.#284
oleaut32.dll.#9
oleaut32.dll.#7
ntdll.dll.EtwUnregisterTraceGuids
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
kernel32.dll.QueryActCtxW
cryptsp.dll.CryptReleaseContext
advapi32.dll.EventUnregister
vssapi.dll.CreateWriter
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
samlib.dll.SamEnumerateDomainsInSamServer
samlib.dll.SamLookupDomainInSamServer
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
oleaut32.dll.#4
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
kernel32.dll.RegCloseKey
kernel32.dll.RegSetValueExW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegQueryValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CreateStreamOnHGlobal
advapi32.dll.RegCreateKeyExW
advapi32.dll.RegSetValueExW
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.IsThreadAFiber
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernelbase.dll.AllocateAndInitializeSid
kernelbase.dll.CheckTokenMembership
kernel32.dll.SetThreadToken
oleaut32.dll.#285
advapi32.dll.RegOpenKeyW
oleaut32.dll.#286
ole32.dll.CLSIDFromString
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
ole32.dll.CoRevertToSelf
advapi32.dll.LogonUserExExW
sspicli.dll.LogonUserExExW
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoGetCallContext
ole32.dll.CoImpersonateClient
advapi32.dll.OpenThreadToken
oleaut32.dll.#8
ole32.dll.CoSwitchCallContext
oleaut32.dll.#287
oleaut32.dll.#288
oleaut32.dll.#289
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
ntmarta.dll.GetMartaExtensionInterface
oleaut32.dll.#290
oleaut32.dll.#150
wtsapi32.dll.WTSEnumerateSessionsW
winsta.dll.WinStationEnumerateW
rpcrt4.dll.I_RpcExceptionFilter
winsta.dll.WinStationFreeMemory
wtsapi32.dll.WTSQuerySessionInformationW
winsta.dll.WinStationQueryInformationW
wtsapi32.dll.WTSFreeMemory
kernel32.dll.GetDiskFreeSpaceExW
kernel32.dll.GetVolumePathNameW
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.Thread32First
kernel32.dll.Thread32Next
kernel32.dll.Process32First
kernel32.dll.Process32Next
kernel32.dll.Module32First
kernel32.dll.Module32Next
kernel32.dll.Heap32ListFirst
kernel32.dll.GetSystemDefaultUILanguage
devobj.dll.DevObjCreateDeviceInfoList
devobj.dll.DevObjGetClassDevs
devobj.dll.DevObjEnumDeviceInfo
devobj.dll.DevObjDestroyDeviceInfoList
user32.dll.GetSystemMetrics
wmi.dll.WmiQueryAllDataW
wmi.dll.WmiQuerySingleInstanceW
wmi.dll.WmiSetSingleItemW
wmi.dll.WmiSetSingleInstanceW
wmi.dll.WmiExecuteMethodW
wmi.dll.WmiNotificationRegistrationW
wmi.dll.WmiMofEnumerateResourcesW
wmi.dll.WmiFileHandleToInstanceNameW
wmi.dll.WmiDevInstToInstanceNameW
wmi.dll.WmiQueryGuidInformation
wmi.dll.WmiOpenBlock
wmi.dll.WmiCloseBlock
wmi.dll.WmiFreeBuffer
wmi.dll.WmiEnumerateGuids
oleaut32.dll.#15
oleaut32.dll.#26
powrprof.dll.PowerDeterminePlatformRole
netapi32.dll.NetGroupEnum
netapi32.dll.NetGroupGetInfo
netapi32.dll.NetGroupSetInfo
netapi32.dll.NetLocalGroupGetInfo
netapi32.dll.NetLocalGroupSetInfo
netapi32.dll.NetGroupGetUsers
netapi32.dll.NetLocalGroupGetMembers
netapi32.dll.NetLocalGroupEnum
netapi32.dll.NetShareEnum
netapi32.dll.NetShareGetInfo
netapi32.dll.NetShareAdd
netapi32.dll.NetShareEnumSticky
netapi32.dll.NetShareSetInfo
netapi32.dll.NetShareDel
netapi32.dll.NetShareDelSticky
netapi32.dll.NetShareCheck
netapi32.dll.NetUserEnum
netapi32.dll.NetUserGetInfo
netapi32.dll.NetUserSetInfo
netapi32.dll.NetApiBufferFree
netapi32.dll.NetQueryDisplayInformation
netapi32.dll.NetServerSetInfo
netapi32.dll.NetServerGetInfo
netapi32.dll.NetGetDCName
netapi32.dll.NetWkstaGetInfo
netapi32.dll.NetGetAnyDCName
netapi32.dll.NetServerEnum
netapi32.dll.NetUserModalsGet
netapi32.dll.NetScheduleJobAdd
netapi32.dll.NetScheduleJobDel
netapi32.dll.NetScheduleJobEnum
netapi32.dll.NetScheduleJobGetInfo
netapi32.dll.NetUseGetInfo
netapi32.dll.NetEnumerateTrustedDomains
netapi32.dll.DsGetDcNameW
netapi32.dll.DsRoleGetPrimaryDomainInformation
netapi32.dll.DsRoleFreeMemory
netapi32.dll.NetRenameMachineInDomain
netapi32.dll.NetJoinDomain
netapi32.dll.NetUnjoinDomain
oleaut32.dll.#40

Execute Commands

C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03_64 Seven03_64 VirtualBox 2017-04-11 14:06:07 2017-04-11 14:08:58 171

3 HTTP Request(s) detected

http://events.fastmediaplayer.net/?p=cHViX2lkPTEwMSZzZXR1cF9pZD0xJmV4dHJhX3BhcmFtcz1PZmZlckluc3RhbGxlciBnbG9iYWwgc3RhcnQgZGlyZWN0JmV2ZW50PTExMSZzaWQ9NjY2Jm1hYz03NzcmYWR2X2lkPTAmYml2ZXJzaW9uPTEuNw==
  • Hostname: events.fastmediaplayer.net
  • IP Address: 52.1.45.42
  • Port: 80
  • Count: 1

GET /?p=cHViX2lkPTEwMSZzZXR1cF9pZD0xJmV4dHJhX3BhcmFtcz1PZmZlckluc3RhbGxlciBnbG9iYWwgc3RhcnQgZGlyZWN0JmV2ZW50PTExMSZzaWQ9NjY2Jm1hYz03NzcmYWR2X2lkPTAmYml2ZXJzaW9uPTEuNw== HTTP/1.1
Host: events.fastmediaplayer.net
Connection: Close

http://events.fastmediaplayer.net/?p=bm9wcm94eT0xJmRvbWFpbj1mYXN0bWVkaWFwbGF5ZXIubmV0JmFkdmlkPTAmcHViaWQ9JmF2PSZiaXZlcnNpb249MS43JmVudj0xJmV2ZW50PTk5JnJlYXNvbj1hZHZfaWQgaXMgZW1wdHkgb3Igd2FzIG5vdCBzdXBwbGllZA==&offer_version=1.7&dotnet=2&osver=6.1
  • Hostname: events.fastmediaplayer.net
  • IP Address: 52.1.45.42
  • Port: 80
  • Count: 1

GET /?p=bm9wcm94eT0xJmRvbWFpbj1mYXN0bWVkaWFwbGF5ZXIubmV0JmFkdmlkPTAmcHViaWQ9JmF2PSZiaXZlcnNpb249MS43JmVudj0xJmV2ZW50PTk5JnJlYXNvbj1hZHZfaWQgaXMgZW1wdHkgb3Igd2FzIG5vdCBzdXBwbGllZA==&offer_version=1.7&dotnet=2&osver=6.1 HTTP/1.1
Host: events.fastmediaplayer.net

http://events.fastmediaplayer.net/?p=bm9wcm94eT0xJmRvbWFpbj1mYXN0bWVkaWFwbGF5ZXIubmV0JmV2ZW50PTk5JmVudj0xJmJpdmVyc2lvbj0xLjcmYXY9JnB1YmlkPSZhZHZpZD0wJnJlYXNvbj1hZHZfaWQgaXMgZW1wdHkgb3Igd2FzIG5vdCBzdXBwbGllZCZpbnN0YWxscGFyYW1zPWVycm9yIGFkdmVydGlzZXIgaXMgbnVsbCZleGl0Y29kZT0w&offer_version=1.7&dotnet=2&osver=6.1
  • Hostname: events.fastmediaplayer.net
  • IP Address: 52.1.45.42
  • Port: 80
  • Count: 1

GET /?p=bm9wcm94eT0xJmRvbWFpbj1mYXN0bWVkaWFwbGF5ZXIubmV0JmV2ZW50PTk5JmVudj0xJmJpdmVyc2lvbj0xLjcmYXY9JnB1YmlkPSZhZHZpZD0wJnJlYXNvbj1hZHZfaWQgaXMgZW1wdHkgb3Igd2FzIG5vdCBzdXBwbGllZCZpbnN0YWxscGFyYW1zPWVycm9yIGFkdmVydGlzZXIgaXMgbnVsbCZleGl0Y29kZT0w&offer_version=1.7&dotnet=2&osver=6.1 HTTP/1.1
Host: events.fastmediaplayer.net

Detected family: #Adware

TheSystem Itself @ 2017-04-11 14:16:02